Sceawere
Vulnerability Detail
CVE-2026-81153UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Robo Gallery Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Robo Gallery
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape some of its image settings before outputting them in a gallery page, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the gallery, including administrators, even where the unfiltered_html capability is disallowed such as on multisite.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-10-11T07:17:24.143Z",
"pubdate": "2026-10-11T07:17:24.143Z",
"executiveSummary": "The Robo Gallery WordPress plugin, specifically versions prior to 5.2.6, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability arises from the failure to properly sanitize and escape image settings before rendering them on the front-end.\nThe vulnerability allows authenticated users with the Author role or higher to inject malicious JavaScript into gallery configurations.\nWhen a victim, including users with higher privileges such as administrators, views a gallery containing the malicious payload, the script executes within the victim's browser context.\nThe risk is significant as it bypasses the unfiltered_html capability restriction, meaning the attack is viable even in hardened multisite environments.\nExploitation allows attackers to perform unauthorized actions on behalf of the victim, potentially leading to full site compromise if an administrator interacts with the malicious payload.",
"technicalDetails": "The vulnerability is located in the image settings management module of the Robo Gallery plugin. The root cause is the insufficient implementation of input sanitization and output escaping for user-supplied data, specifically image attributes or settings that are saved to the database.\nWhen an authenticated user with at least Author-level permissions modifies gallery settings, the plugin fails to strip malicious scripts or encode them properly before storing them in the WordPress database. Because the plugin does not apply appropriate security functions such as esc_attr(), esc_html(), or sanitize_text_field() upon output, these stored malicious scripts are rendered directly into the HTML of the gallery page.\nThe attack flow follows a clear progression: 1) The authenticated attacker navigates to the Robo Gallery settings page. 2) The attacker injects a malicious JavaScript payload into an affected image setting field. 3) The plugin saves this unsanitized string directly into the database. 4) When any user, including an administrator, views the gallery page, the server fetches the malicious string from the database and embeds it into the HTML response without transformation. 5) The victim's browser interprets the injected payload as legitimate code, resulting in execution within the victim's session.\nThis vulnerability is particularly critical because it persists across sessions. The exploit is executed client-side, allowing the attacker to perform actions such as stealing session cookies, capturing sensitive information, or executing administrative actions via CSRF (Cross-Site Request Forgery) if the victim is a privileged user. The impact is elevated because it circumvents the 'unfiltered_html' restriction, which is intended to prevent low-privileged users from adding dangerous code. By leveraging the plugin's internal handling of settings, the attacker bypasses the core security controls of the WordPress installation, exposing the integrity and confidentiality of the entire site."
}