InPost Gallery <= 2.1.4.6 - Unauthenticated SQL Injection
high
The InPost Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries...
- CVSS:
- 7.5
- Affected:
- up to 2.1.4.6
- Fixed in:
- 2.1.5
- Disclosed:
- Apr 20, 2026
CVE-2026-39574 on NVD →
InPost Gallery [inpost-gallery] < 2.1.4.6
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 InPost Gallery allows PHP Local File Inclusion. This issue affects InPost Gallery: from n/a through 2.1.4.5.
- Affected:
- up to 2.1.4.6
- Fixed in:
- 2.1.4.6
- Disclosed:
- Sep 5, 2025
CVE-2025-57889 on NVD →
InPost Gallery <= 2.1.4.5 - Authenticated (Subscriber+) Local File Inclusion
high
The InPost Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.4.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files...
- CVSS:
- 8.8
- Affected:
- up to 2.1.4.5
- Fixed in:
- 2.1.4.6
- Disclosed:
- Sep 3, 2025
CVE-2025-57889 on NVD →
InPost Gallery [inpost-gallery] < 2.1.4.4 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in RealMag777 InPost Gallery allows Cross Site Request Forgery. This issue affects InPost Gallery: from n/a through 2.1.4.3.
- Affected:
- up to 2.1.4.4
- Fixed in:
- 2.1.4.4
- Disclosed:
- Apr 15, 2025
CVE-2025-26903 on NVD →
InPost Gallery <= 2.1.4.3 - Cross-Site Request Forgery
medium
The InPost Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.4.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site admi...
- CVSS:
- 4.3
- Affected:
- up to 2.1.4.3
- Fixed in:
- 2.1.4.4
- Disclosed:
- Apr 11, 2025
CVE-2025-26903 on NVD →
InPost Gallery [inpost-gallery] < 2.1.4.3 (closed)
unknown
[en] The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_shortcode_template AJAX action in all versions up to, and including, 2.1.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running...
- Affected:
- up to 2.1.4.3
- Fixed in:
- 2.1.4.3
- Disclosed:
- Nov 26, 2024
CVE-2024-11002 on NVD →
InPost Gallery <= 2.1.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via inpost_gallery_get_shortcode_template
medium
The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_shortcode_template AJAX action in all versions up to, and including, 2.1.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_sh...
- CVSS:
- 6.3
- Affected:
- up to 2.1.4.2
- Fixed in:
- 2.1.4.3
- Disclosed:
- Nov 25, 2024
CVE-2024-11002 on NVD →
InPost Gallery [inpost-gallery] < 2.1.4.2 (closed)
unknown
[en] The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'imgurl' parameter to the add_inpost_gallery_slide_item action, which can only be triggered by an authenticated user.
- Affected:
- up to 2.1.4.2
- Fixed in:
- 2.1.4.2
- Disclosed:
- Mar 22, 2023
CVE-2023-28666 on NVD →
InPost Gallery <= 2.1.4.1 - Reflected Cross-Site Scripting via 'imgurl'
medium
The InPost Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘imgurl’ parameter of the add_inpost_gallery_slide_item action in versions up to, and including, 2.1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj...
- CVSS:
- 6.1
- Affected:
- up to 2.1.4.1
- Fixed in:
- 2.1.4.2
- Disclosed:
- Mar 20, 2023
CVE-2023-28666 on NVD →
InPost Gallery [inpost-gallery] < 2.1.4.1 (closed)
unknown
[en] The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.
- Affected:
- up to 2.1.4.1
- Fixed in:
- 2.1.4.1
- Disclosed:
- Dec 19, 2022
CVE-2022-4063 on NVD →
InPost Gallery <= 2.1.4.1 - Local File Inclusion
critical
The InPost Gallery Plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.4 via the popup_shortcode_key parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used...
- CVSS:
- 9.8
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.4.1
- Disclosed:
- Nov 28, 2022
CVE-2022-4063 on NVD →
InPost Gallery < 2.1.2.1 - Local File Inclusion
critical
The InPost Gallery Plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 via the popup_shortcode_key parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used...
- CVSS:
- 9.8
- Affected:
- up to 2.1.2.1
- Fixed in:
- 2.1.2.1
- Disclosed:
- Oct 20, 2016
InPost Gallery [inpost-gallery] < 2.1.2.1 (closed)
unknown
The InPost Gallery Plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 via the popup_shortcode_key parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used...
- Affected:
- up to 2.1.2.1
- Fixed in:
- 2.1.2.1
- Disclosed:
- Oct 20, 2016
InPost Gallery [inpost-gallery] < 2.1.2.1 (closed)
unknown
WordPress InPost Gallery plugin is prone to a local file inclusion vulnerability. The value of “popup_shortcode_key”, in to the function render_html() is not validated and later it is included.
Update the plugin.
- Affected:
- up to 2.1.2.1
- Fixed in:
- 2.1.2.1
- Disclosed:
- Oct 20, 2016
InPost Gallery [inpost-gallery] < 2.1.2.1 (closed)
unknown
WordPress InPost Gallery plugin version <= 2.1.2 is vulnerable to Cross-Site (XSS) vulnerability. The values on the admin settings page are not escaped.
Update the plugin.
- Affected:
- up to 2.1.2.1
- Fixed in:
- 2.1.2.1
- Disclosed:
- Oct 20, 2016
InPost Gallery <= 2.1.2 - Cross-Site Scripting
medium
The InPost Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'admin_thumb_width' parameter in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above,...
- CVSS:
- 6.4
- Affected:
- up to 2.1.2.1
- Fixed in:
- 2.1.2.1
- Disclosed:
- Oct 18, 2016
InPost Gallery [inpost-gallery] < 2.1.2.1 (closed)
unknown
The InPost Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'admin_thumb_width' parameter in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above,...
- Affected:
- up to 2.1.2.1
- Fixed in:
- 2.1.2.1
- Disclosed:
- Oct 18, 2016
InPost Gallery [inpost-gallery] < 2.1.2.1 (closed)
unknown
The InPost Gallery WordPress plugin was affected by a LFI & Authenticated Stored XSS security vulnerability.
- Affected:
- up to 2.1.2.1
- Fixed in:
- 2.1.2.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database