Loading
The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.
Use CWE-22, Pluginus vendor hub and Inpost Gallery product page to widen CVE-2022-4063 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-11002 and CVE-2023-28666 for nearby disclosures in the same product family.