CVE-2023-0467
WP Dark Mode < 4.0.8 - Subscriber+ Local File Inclusion
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The WP Dark Mode WordPress plugin before 4.0.8 does not properly sanitize the style parameter in shortcodes before using it to load a PHP template. This leads to Local File Inclusion on servers where non-existent directories may be traversed, or when chained with another vulnerability allowing arbitrary directory creation.
The WP Dark Mode plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.7 via the 'style' shortcode attribute. This allows authenticated attackers, with subscriber-level permissions and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. This only affects installations where the traversal of non-existent directories is allowed or when chained with another vulnerability that allows for the creation of arbitrary directories.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-01-24 CVE Reserved
- 2023-03-06 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/8eb431a6-59a5-4cee-84e0-156c0b31cfc4 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wppool Search vendor "Wppool" | Wp Dark Mode Search vendor "Wppool" for product "Wp Dark Mode" | < 4.0.8 Search vendor "Wppool" for product "Wp Dark Mode" and version " < 4.0.8" | wordpress |
Affected
|