Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin <= 1.0.0 on WordPress via vulnerable parameters: &ntmode_page_setting[enable-me], &ntmode_page_setting[bg-color], &ntmode_page_setting[txt-color], &ntmode_page_setting[anc_color].
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-33756 | Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin <= 1.0.0 on WordPress via vulnerable parameters: &ntmode_page_setting[enable-me], &ntmode_page_setting[bg-color], &ntmode_page_setting[txt-color], &ntmode_page_setting[anc_color]. |
Fixes
Solution
Update to 1.4.0 or higher version.
Workaround
No workaround given by the vendor.
References
History
Thu, 20 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-02-20T20:25:40.040Z
Reserved: 2022-04-18T00:00:00.000Z
Link: CVE-2022-29418
Updated: 2024-08-03T06:17:55.347Z
Status : Modified
Published: 2022-04-25T17:15:37.457
Modified: 2024-11-21T06:59:02.593
Link: CVE-2022-29418
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD