CVE-2025-26903: WordPress InPost Gallery plugin <= 2.1.4.3 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in RealMag777 InPost Gallery allows Cross Site Request Forgery. This issue affects InPost Gallery: from n/a through 2.1.4.3.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in RealMag777 InPost Gallery inpost-gallery allows Cross Site Request Forgery.This issue affects InPost Gallery: from n/a through <= 2.1.4.3.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26903?
CVE-2025-26903 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can potentially allow attackers to execute unauthorized actions on behalf of authenticated users.
How do I fix CVE-2025-26903?
To fix CVE-2025-26903, update the RealMag777 InPost Gallery plugin to the latest version beyond 2.1.4.3.
Who is affected by CVE-2025-26903?
CVE-2025-26903 affects users of the RealMag777 InPost Gallery and WordPress InPost Gallery plugin up to version 2.1.4.3.
What types of attacks can CVE-2025-26903 enable?
CVE-2025-26903 can enable attackers to execute unauthorized actions by tricking authenticated users into submitting requests they did not intend.
Is CVE-2025-26903 a low-risk vulnerability?
While the risk level can vary based on the specific implementation and user actions, CSRF vulnerabilities like CVE-2025-26903 are generally considered serious due to their ability to compromise user accounts.