← Back to browse · API

CVE-2022-4063

Severity
CRITICAL
CVSS
9.8
EPSS
0.09519
Risk score
42.53
CISA KEV
No
PoC
No
Published
2022-12-19
Modified
2025-04-17
First seen
2026-08-07
Aliases
EUVD-2022-51440, GHSA-5RMH-7P7V-FMFC
Products
realmag777:InPost Gallery 0 <2.1.4.1
Sources
euvd EUVD-2022-51440

Description

The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.

References