CVE-2026-39574
Description
Unauthenticated SQL injection in InPost Gallery <= 2.1.4.6 allows remote attackers to interact with the database, leading to data theft.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated SQL injection in InPost Gallery <= 2.1.4.6 allows remote attackers to interact with the database, leading to data theft.
Vulnerability
An unauthenticated SQL injection vulnerability exists in the InPost Gallery plugin for WordPress, affecting versions 2.1.4.6 and earlier. The vulnerability allows an attacker to inject arbitrary SQL queries without requiring any authentication or prior knowledge of the site [1].
Exploitation
An attacker can exploit this vulnerability remotely over HTTP by sending specially crafted requests to the vulnerable plugin endpoint. No authentication or user interaction is required. The low complexity of exploitation makes it attractive for mass-exploit campaigns targeting thousands of websites simultaneously [1].
Impact
Successful exploitation allows an attacker to directly interact with the database, potentially extracting sensitive information such as user credentials, personal data, or other stored content. The CVSS score of 9.3 (Critical) reflects the high impact on confidentiality, with no privileges required and no user interaction needed [1].
Mitigation
The vendor has released version 2.1.5 which fixes the vulnerability. Users should update to version 2.1.5 or later immediately. For those unable to update, a mitigation rule from Patchstack is available to block attacks until the update is applied. Auto-update can be enabled for vulnerable plugins [1].
AI Insight generated on Jun 16, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=2.1.4.6+ 1 more
- (no CPE)range: <=2.1.4.6
- (no CPE)range: <=2.1.4.6
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.