← WordPress Vulnerabilities
WordPress security by component

Catch Dark Mode

Catch Dark Mode is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 17, 2025; the highest published CVSS base score is 7.5.

Plugin slug: catch-dark-mode

CVE-2025-10143: Catch Dark Mode: Filesystem traversal

Catch Dark Mode is affected by filesystem traversal. Exploitation requires an authenticated contributor account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedSep 17, 2025
Safe version guidanceSee mitigation notes
Published vulnerabilities for catch-dark-mode
Safe version
Sep 17, 2025 CVE-2025-10143
Catch Dark Mode: Filesystem traversal
Catch Dark Mode is affected by filesystem traversal. Exploitation requires an authenticated contributor account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.5
NVDPending
Apr 04, 2025 CVE-2025-32154
Catch Dark Mode: Filesystem traversal
Catch Dark Mode is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.5
NVD8.8