WordPress Plugin Vulnerabilities

Robo Gallery < 5.2.6 - Author+ Stored XSS via Image Overlay Effect Meta

Description

The plugin does not sanitise and escape some of its image settings before outputting them in a gallery page, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the gallery, including administrators, even where the unfiltered_html capability is disallowed such as on multisite.

Proof of Concept

Affects Plugins

Fixed in 5.2.6

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Kenneth Billones
Submitter
Kenneth Billones
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-10-09 (about 2 days ago)
Added
2026-10-09 (about 1 day ago)
Last Updated
2026-10-09 (about 1 day ago)

Other