plugin

Inpost Gallery Vulnerabilities

18 known security issues reported for the Inpost Gallery WordPress plugin. Most recent disclosed Apr 20, 2026.

2 critical 2 high 4 medium

Running Inpost Gallery on your site? Check whether your installed version is affected.

Scan your site free

InPost Gallery <= 2.1.4.6 - Unauthenticated SQL Injection

high

The InPost Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries...

CVSS:
7.5
Affected:
up to 2.1.4.6
Fixed in:
2.1.5
Disclosed:
Apr 20, 2026

CVE-2026-39574 on NVD →

InPost Gallery [inpost-gallery] < 2.1.4.6

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 InPost Gallery allows PHP Local File Inclusion. This issue affects InPost Gallery: from n/a through 2.1.4.5.

Affected:
up to 2.1.4.6
Fixed in:
2.1.4.6
Disclosed:
Sep 5, 2025

CVE-2025-57889 on NVD →

InPost Gallery <= 2.1.4.5 - Authenticated (Subscriber+) Local File Inclusion

high

The InPost Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.4.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files...

CVSS:
8.8
Affected:
up to 2.1.4.5
Fixed in:
2.1.4.6
Disclosed:
Sep 3, 2025

CVE-2025-57889 on NVD →

InPost Gallery [inpost-gallery] < 2.1.4.4 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in RealMag777 InPost Gallery allows Cross Site Request Forgery. This issue affects InPost Gallery: from n/a through 2.1.4.3.

Affected:
up to 2.1.4.4
Fixed in:
2.1.4.4
Disclosed:
Apr 15, 2025

CVE-2025-26903 on NVD →

InPost Gallery <= 2.1.4.3 - Cross-Site Request Forgery

medium

The InPost Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.4.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site admi...

CVSS:
4.3
Affected:
up to 2.1.4.3
Fixed in:
2.1.4.4
Disclosed:
Apr 11, 2025

CVE-2025-26903 on NVD →

InPost Gallery [inpost-gallery] < 2.1.4.3 (closed)

unknown

[en] The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_shortcode_template AJAX action in all versions up to, and including, 2.1.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running...

Affected:
up to 2.1.4.3
Fixed in:
2.1.4.3
Disclosed:
Nov 26, 2024

CVE-2024-11002 on NVD →

InPost Gallery <= 2.1.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via inpost_gallery_get_shortcode_template

medium

The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_shortcode_template AJAX action in all versions up to, and including, 2.1.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_sh...

CVSS:
6.3
Affected:
up to 2.1.4.2
Fixed in:
2.1.4.3
Disclosed:
Nov 25, 2024

CVE-2024-11002 on NVD →

InPost Gallery [inpost-gallery] < 2.1.4.2 (closed)

unknown

[en] The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'imgurl' parameter to the add_inpost_gallery_slide_item action, which can only be triggered by an authenticated user.

Affected:
up to 2.1.4.2
Fixed in:
2.1.4.2
Disclosed:
Mar 22, 2023

CVE-2023-28666 on NVD →

InPost Gallery <= 2.1.4.1 - Reflected Cross-Site Scripting via 'imgurl'

medium

The InPost Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘imgurl’ parameter of the add_inpost_gallery_slide_item action in versions up to, and including, 2.1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj...

CVSS:
6.1
Affected:
up to 2.1.4.1
Fixed in:
2.1.4.2
Disclosed:
Mar 20, 2023

CVE-2023-28666 on NVD →

InPost Gallery [inpost-gallery] < 2.1.4.1 (closed)

unknown

[en] The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.

Affected:
up to 2.1.4.1
Fixed in:
2.1.4.1
Disclosed:
Dec 19, 2022

CVE-2022-4063 on NVD →

InPost Gallery <= 2.1.4.1 - Local File Inclusion

critical

The InPost Gallery Plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.4 via the popup_shortcode_key parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used...

CVSS:
9.8
Affected:
up to 2.1.4
Fixed in:
2.1.4.1
Disclosed:
Nov 28, 2022

CVE-2022-4063 on NVD →

InPost Gallery < 2.1.2.1 - Local File Inclusion

critical

The InPost Gallery Plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 via the popup_shortcode_key parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used...

CVSS:
9.8
Affected:
up to 2.1.2.1
Fixed in:
2.1.2.1
Disclosed:
Oct 20, 2016

InPost Gallery [inpost-gallery] < 2.1.2.1 (closed)

unknown

The InPost Gallery Plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 via the popup_shortcode_key parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used...

Affected:
up to 2.1.2.1
Fixed in:
2.1.2.1
Disclosed:
Oct 20, 2016

InPost Gallery [inpost-gallery] < 2.1.2.1 (closed)

unknown

WordPress InPost Gallery plugin is prone to a local file inclusion vulnerability. The value of “popup_shortcode_key”, in to the function render_html() is not validated and later it is included. Update the plugin.

Affected:
up to 2.1.2.1
Fixed in:
2.1.2.1
Disclosed:
Oct 20, 2016

InPost Gallery [inpost-gallery] < 2.1.2.1 (closed)

unknown

WordPress InPost Gallery plugin version <= 2.1.2 is vulnerable to Cross-Site (XSS) vulnerability. The values on the admin settings page are not escaped. Update the plugin.

Affected:
up to 2.1.2.1
Fixed in:
2.1.2.1
Disclosed:
Oct 20, 2016

InPost Gallery <= 2.1.2 - Cross-Site Scripting

medium

The InPost Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'admin_thumb_width' parameter in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above,...

CVSS:
6.4
Affected:
up to 2.1.2.1
Fixed in:
2.1.2.1
Disclosed:
Oct 18, 2016

InPost Gallery [inpost-gallery] < 2.1.2.1 (closed)

unknown

The InPost Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'admin_thumb_width' parameter in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above,...

Affected:
up to 2.1.2.1
Fixed in:
2.1.2.1
Disclosed:
Oct 18, 2016

InPost Gallery [inpost-gallery] < 2.1.2.1 (closed)

unknown

The InPost Gallery WordPress plugin was affected by a LFI &amp; Authenticated Stored XSS security vulnerability.

Affected:
up to 2.1.2.1
Fixed in:
2.1.2.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database