Junglewise Threat Intelligence

CVE-2026-39574: InPost Gallery unauthenticated SQL injection

CVE-2026-39574 · Severity: critical · CVSS 9.3 · Published 2026-06-16

Executive brief

InPost Gallery is a WordPress plugin used to create and manage photo galleries on websites. A critical security flaw allows unauthorized individuals to interact directly with the website's database without needing a password. This could lead to the theft of sensitive customer data, administrative credentials, or a complete compromise of the website's information.

Technical details

A SQL injection vulnerability (CWE-89) exists in the InPost Gallery plugin for WordPress due to improper neutralization of special elements in SQL commands. The flaw is accessible to unauthenticated remote attackers over the network with low attack complexity. By sending specially crafted requests, an attacker can bypass authentication and directly query the underlying database, potentially leading to full data exfiltration or unauthorized modifications. The vulnerability affects all versions up to and including 2.1.4.6 and has been addressed in version 2.1.5.

Affected products

  • InPost Gallery InPost Gallery <= 2.1.4.6

Timeline

  • 2026-02-19: other: Reported by hivesec
  • 2026-04-20: advisory: Patchstack advisory published
  • 2026-06-16: disclosed: NVD publication date

References