CVE-2022-4063: InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4063?
CVE-2022-4063 is a vulnerability in the InPost Gallery WordPress plugin before version 2.1.4.1 that allows attackers to force the inclusion of malicious files and URLs, potentially enabling them to run code on servers.
How severe is CVE-2022-4063?
CVE-2022-4063 has a severity rating of critical with a score of 9.8.
What software is affected by CVE-2022-4063?
The InPost Gallery WordPress plugin before version 2.1.4.1 is affected by CVE-2022-4063.
How can an attacker exploit CVE-2022-4063?
An attacker can exploit CVE-2022-4063 by leveraging the insecure usage of the PHP extract() function in the InPost Gallery WordPress plugin to force the inclusion of malicious files and URLs.
How can CVE-2022-4063 be fixed?
To fix CVE-2022-4063, it is recommended to update the InPost Gallery WordPress plugin to version 2.1.4.1 or later.