CVE-2025-57889 | RealMag777 InPost Gallery Plugin up to 2.1.4.5 on WordPress filename control
A vulnerability, which was classified as problematic, was found in RealMag777 InPost Gallery Plugin up to 2.1.4.5 on WordPress. The impacted element is an unknown function. Executing manipulation can lead to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is tracked as CVE-2025-57889. The attack can be launched remotely. No exploit exists.