Showing 1 vulnerability on this page for inpost_gallery

Signals CISA KEV Ransomware Nuclei
pluginus vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE

The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.

CWE-22Dec 19, 20221 related artifact
CVSS9.8v3.1EPSS9.52%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX