Impact
The vulnerability lies in an inadequate validation of filenames used in include/require calls within the InPost Gallery plugin. This flaw can allow an attacker to inject a pathname that references arbitrary files on the server, potentially leading to the execution of malicious PHP code or unauthorised disclosure of sensitive data. Satisfying the CWE‑98 weakness, the flaw is capable of turning the plugin into an execution vector if the attacker can supply a crafted parameter.
Affected Systems
RealMag777’s InPost Gallery WordPress plugin is affected. All releases from the initial release up to and including version 2.1.4.5 are susceptible. The plugin is used on WordPress sites where it provides gallery functionality.
Risk and Exploitability
The flaw carries a CVSS score of 7.5, indicating a high impact vulnerability. The EPSS score is below 1 %, suggesting that, while the risk is high, the likelihood of exploitation at this time is low. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely target the plugin through HTTP requests that supply a manipulated query or form value; local file inclusion can be exploited when the server has erroneously exposed writable directories or when the plugin fails to restrict the include path.
OpenCVE Enrichment
EUVD