CVE-2022-4063
19.12.2022, 14:15
The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.
Vendor | Product | Version |
---|---|---|
pluginus | inpost_gallery | 𝑥 < 2.1.4.1 |
𝑥
= Vulnerable software versions