InPost Gallery
InPost Gallery has 8 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2026; all 8 are fixed as of September 2026. Their average CVSS score is 7.4, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 2 high. 2025 was the busiest year with 2 disclosures.
The most common weakness is PHP Remote File Inclusion, behind 3 of the records (38%). Other recurring categories include Cross-Site Scripting, Code Injection.
Every one of the 8 issues recorded for InPost Gallery has a vendor fix available, so running the current release closes all known holes.
6 independent researchers contributed these findings, one record each. InPost Gallery is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2022-4063InPost Gallery <= 2.1.4.1 - Local File Inclusion
Read the full analysisVulnerability Records

InPost Gallery
Author
RealMag777
InPost Gallery – Powerful and very pleasant photo gallery plugin to work with images in WordPress. 5 galleries in one plugin. Do not read documentations – install and use! Unique functionality: Each gallery can be presented on the page as one clickable image!!! Insert such little image in any widget, and your customers will be able to watch big galleries by one click! The Backend is powered with visual shortcodes management where you only by mouse can change view of your post gallery on front. You do not need go to another pages with amount of options. Just install and use, all you need it is popup with shortcode options in your current page editor. Good for photographers and portfolios. The plugin can be used as woocommerce images gallery Supports: multiple images uploading, css effects (like round corners of images with shadow). PHP 8.x compatible! License This plugin is copyright pluginus.net ©2012-2026 with GNU General Public License by realmag777. This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY. See the GNU General Public License for more details.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C