VendorsPluginUsinpost_galleryall versions
Vulnerabilities

PluginUs InPost Gallery 2.1.4.1 for WordPress

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2022-4063
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
Published 2022-12-19 · Modified
9.8EPSS 0.095
CVE-2024-11002
InPost Gallery <= 2.1.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via inpost_gallery_get_shortcode_template
Published 2024-11-26 · Analyzed
6.3EPSS 0.006
CVE-2023-28666
The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'imgurl' parameter to the add_inpost_gallery_slide_item action, which can only be triggered by an authenticated user.
Published 2023-03-22 · Modified
5.4EPSS 0.004