SQL Injection Vulnerability in InPost Gallery Plugin for WordPress
CVE-2026-39574

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 June 2026

What is CVE-2026-39574?

The InPost Gallery plugin for WordPress is susceptible to an unauthenticated SQL injection vulnerability that affects versions up to 2.1.4.6. This flaw allows attackers to execute arbitrary SQL queries against the database without authentication, potentially leading to unauthorized data access, data manipulation, or even complete takeover of the affected website. Website administrators are urged to apply security updates and mitigate risks by ensuring they are running the latest version of the plugin.

Affected Version(s)

InPost Gallery <= 2.1.4.6

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hivesec | Patchstack Bug Bounty Program
.