Local File Inclusion Vulnerability in RealMag777 InPost Gallery Plugin
CVE-2025-57889
7.5HIGH
What is CVE-2025-57889?
The RealMag777 InPost Gallery plugin is susceptible to a Local File Inclusion vulnerability due to improper control of the filename in PHP include or require statements. This flaw allows attackers to exploit the system by including unintended files, potentially leading to malicious code execution and unauthorized access to sensitive information. Affected versions include all prior to 2.1.4.5, making immediate updates crucial for maintaining site security.
Affected Version(s)
InPost Gallery <= 2.1.4.5