CVE-2025-57889: WordPress InPost Gallery Plugin <= 2.1.4.5 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 InPost Gallery allows PHP Local File Inclusion. This issue affects InPost Gallery: from n/a through 2.1.4.5.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 InPost Gallery inpost-gallery allows PHP Local File Inclusion.This issue affects InPost Gallery: from n/a through <= 2.1.4.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57889?
CVE-2025-57889 is classified as a high severity vulnerability due to its potential for remote file inclusion and local file inclusion attacks.
How do I fix CVE-2025-57889?
To fix CVE-2025-57889, update the RealMag777 InPost Gallery to version 2.1.4.6 or later to mitigate the vulnerability.
What versions of InPost Gallery are affected by CVE-2025-57889?
CVE-2025-57889 affects versions from n/a to 2.1.4.5 of the RealMag777 InPost Gallery and WordPress InPost Gallery Plugin.
What type of vulnerability is CVE-2025-57889?
CVE-2025-57889 is an improper control of filename vulnerability that allows for PHP local file inclusion.
Can CVE-2025-57889 lead to unauthorized access?
Yes, CVE-2025-57889 can lead to unauthorized access to local files on the server due to file inclusion vulnerabilities.