WordPress security by component
Catch Dark Mode
Plugin description
Catch Dark Mode is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 17, 2025; the highest published CVSS base score is 7.5.
Plugin slug:
catch-dark-modeLatest vulnerability
CVE-2025-10143: Catch Dark Mode: Filesystem traversal
Catch Dark Mode is affected by filesystem traversal. Exploitation requires an authenticated contributor account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Sep 17, 2025 |
CVE-2025-10143
Catch Dark Mode: Filesystem traversal
Catch Dark Mode is affected by filesystem traversal. Exploitation requires an authenticated contributor account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Apr 04, 2025 |
CVE-2025-32154
Catch Dark Mode: Filesystem traversal
Catch Dark Mode is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.5
NVD8.8
|