First published: Mon Dec 19 2022(Updated: )
The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pluginus Inpost Gallery | <2.1.4.1 | |
<2.1.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4063 is a vulnerability in the InPost Gallery WordPress plugin before version 2.1.4.1 that allows attackers to force the inclusion of malicious files and URLs, potentially enabling them to run code on servers.
CVE-2022-4063 has a severity rating of critical with a score of 9.8.
The InPost Gallery WordPress plugin before version 2.1.4.1 is affected by CVE-2022-4063.
An attacker can exploit CVE-2022-4063 by leveraging the insecure usage of the PHP extract() function in the InPost Gallery WordPress plugin to force the inclusion of malicious files and URLs.
To fix CVE-2022-4063, it is recommended to update the InPost Gallery WordPress plugin to version 2.1.4.1 or later.