CVE-2023-28666: Pluginus Inpost Gallery

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'imgurl' parameter to the add_inpost_gallery_slide_item action, which can only be triggered by an authenticated user.

Affected products

  • Pluginus Inpost Gallery: up to and including 2.1.4.1

Published 2023-03-22. Last modified 2026-06-17.