Medium severity4.8NVD Advisory· Published Apr 25, 2022· Updated Jun 17, 2026
CVE-2022-29418
CVE-2022-29418
Description
Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin <= 1.0.0 on WordPress via vulnerable parameters: &ntmode_page_setting[enable-me], &ntmode_page_setting[bg-color], &ntmode_page_setting[txt-color], &ntmode_page_setting[anc_color].
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=1.0.0
- cpe:2.3:a:night_mode_project:night_mode:*:*:*:*:*:wordpress:*:*Range: <=1.0.0
- Mark Daniels/Night Mode (WordPress plugin)v5Range: <= 1.0.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.