CVE-2025-47628: WordPress QS Dark Mode plugin <= 3.0 - Broken Access Control Vulnerability
Published May 7, 2025
·Updated
Missing Authorization vulnerability in quomodosoft QS Dark Mode qs-dark-mode allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects QS Dark Mode: from n/a through <= 3.0.
Affected Software
3 affected components
QuomodoSoft Qs Dark Mode Wordpress<=3.0
QuomodoSoft QS Dark Mode<=3.0
WordPress QS Dark Mode<=3.0
Event History
May 7, 2025
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-47628?
CVE-2025-47628 is classified as a high severity vulnerability due to its impact on access control.
2
How do I fix CVE-2025-47628?
To fix CVE-2025-47628, you should update the QS Dark Mode plugin to version 3.1 or later.
3
What versions of QS Dark Mode are affected by CVE-2025-47628?
CVE-2025-47628 affects all versions of QS Dark Mode up to and including version 3.0.
4
What type of vulnerability is CVE-2025-47628?
CVE-2025-47628 is a missing authorization vulnerability that enables exploitation of improperly configured access control.
5
Who is impacted by CVE-2025-47628?
Users of the QS Dark Mode plugin for WordPress versions up to 3.0 are directly impacted by CVE-2025-47628.