peter bassill · operator
$ cve CVE-2022-4063 JSON

CVE-2022-4063

9.8
CRITICAL · CVSS 3.1 · EPSS 9.6% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS9.62% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploitnone known
Published2022-12-19
Last modified2026-06-17

Affected (1)

VendorProduct
pluginusinpost gallery

References

→ the Explorer  ·  watch your stack  ·  NVD