VYPR
Critical severity9.3NVD Advisory· Published Jun 16, 2026· Updated Jun 16, 2026

CVE-2026-39574

CVE-2026-39574

Description

Unauthenticated SQL injection in InPost Gallery <= 2.1.4.6 allows remote attackers to interact with the database, leading to data theft.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated SQL injection in InPost Gallery <= 2.1.4.6 allows remote attackers to interact with the database, leading to data theft.

Vulnerability

An unauthenticated SQL injection vulnerability exists in the InPost Gallery plugin for WordPress, affecting versions 2.1.4.6 and earlier. The vulnerability allows an attacker to inject arbitrary SQL queries without requiring any authentication or prior knowledge of the site [1].

Exploitation

An attacker can exploit this vulnerability remotely over HTTP by sending specially crafted requests to the vulnerable plugin endpoint. No authentication or user interaction is required. The low complexity of exploitation makes it attractive for mass-exploit campaigns targeting thousands of websites simultaneously [1].

Impact

Successful exploitation allows an attacker to directly interact with the database, potentially extracting sensitive information such as user credentials, personal data, or other stored content. The CVSS score of 9.3 (Critical) reflects the high impact on confidentiality, with no privileges required and no user interaction needed [1].

Mitigation

The vendor has released version 2.1.5 which fixes the vulnerability. Users should update to version 2.1.5 or later immediately. For those unable to update, a mitigation rule from Patchstack is available to block attacks until the update is applied. Auto-update can be enabled for vulnerable plugins [1].

AI Insight generated on Jun 16, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.