S4E just found a medium ssl lucky13 vulnerability scanner
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2022-4063 Scanner

Detects 'Code Injection' vulnerability in InPost Gallery plugin for WordPress affects v. before 2.1.4.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-4063
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
InPost Gallery
AFFECTED< 2.1.4.1SAFE ✓≥ 2.1.4.1
Updated Aug 22, 2026View on NVD →
Detail

The InPost Gallery is a popular WordPress plugin used for creating and managing photo galleries on websites. This plugin is particularly useful for those who want to showcase their photos in a professional and aesthetically pleasing manner. With multiple themes, different display modes, and easy configuration options, it has become a go-to plugin for many website owners to present their photography.

However, this plugin is not immune to vulnerabilities. CVE-2022-4063 is one such vulnerability that has been detected in the InPost Gallery plugin before version 2.1.4.1. The exploit is related to the plugin’s use of PHP's extract() function when rendering HTML views. Unauthorised attackers could use this vulnerability to force the inclusion of malicious files and URLs, thereby allowing them to run code on servers.

The potential consequences of this vulnerability could be disastrous for website owners. If exploited, the attacker may gain control over the website, install malware, steal sensitive data, or use the server as part of a larger botnet. The attacker can also create NEW user accounts, with admin privileges, acting as a stepping stone for future attacks.

As the number of digital assets website owners need to manage grows, so does the need for reliable and up-to-date security information. With the pro features of s4e.io, it is easy to stay informed about vulnerabilities in digital assets that website owners depend on. By subscribing to s4e.io, the user can receive alerts on their mobile, tablet, and desktop emails, and thus, remain aware of updates and vulnerabilities. So, stay safe and informed by using s4e.io, and sleep soundly knowing that the safety of your website is in good hands.

 

REFERENCES

Solution Advice

Thankfully, there are some precautions that website owners can take to protect their sites from this vulnerability, such as:

  • Updating the InPost Gallery plugin or removing it altogether
  • Implementing a web application firewall to detect and prevent attacks
  • Conducting regular scans of the website for malware and other threats
  • Limiting access to the server files and directories where the plugin is installed

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-4063 scanner - Code Injection vulnerability in InPost Gallery plugin for WordPress S4E