Sceawere

Vulnerability Detail

CVE-2026-81154UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Robo Gallery Stored XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
8h ago
Vendor
Unknown
Product
Robo Gallery
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape image alt text before outputting it in one of its gallery layouts, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected gallery, including administrators.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-10-11T07:17:24.267Z",
  "pubdate": "2026-10-11T07:17:24.267Z",
  "executiveSummary": "The Robo Gallery WordPress plugin, specifically versions prior to 5.2.6, contains a Stored Cross-Site Scripting (XSS) vulnerability.\nThis flaw arises from the improper sanitization and escaping of image alt text attributes before they are rendered in specific gallery layouts.\nThe vulnerability allows authenticated users with the Author role or higher to inject malicious JavaScript into the application, which is subsequently stored in the database.\nWhen an unsuspecting user—including administrative accounts—views the compromised gallery, the malicious payload executes within their browser session.\nThe impact of this vulnerability is significant, as it permits unauthorized actors to perform actions on behalf of the victim, potentially leading to full site compromise, account takeover, or session hijacking depending on the victim's privileges.\nExploitation is restricted to authenticated users with Author-level privileges or higher, meaning the attack surface is limited to internal users, though this represents a critical risk in multi-author environments.",
  "technicalDetails": "The root cause of the vulnerability is an input validation failure where the Robo Gallery plugin fails to apply adequate sanitization and output escaping to the image alt text field.\nWordPress plugins are expected to use security functions such as esc_attr() when echoing metadata into HTML attributes. In this instance, the plugin directly embeds user-provided string input into the gallery markup without filtration.\nAn authenticated attacker with 'Author' privileges or higher can navigate to the gallery settings or image management interface and supply a crafted XSS payload within the alt text field of an image.\nWhen the gallery is rendered on the front end of the site, the browser interprets the malicious content as executable code rather than a static string. For instance, an attacker might inject a payload such as '><script>alert(document.cookie)</script>.\nThe attack flow follows a predictable pattern: first, the attacker injects the payload via the image meta fields. Second, the server stores this payload in the WordPress database associated with the image metadata. Third, when a victim navigates to a page displaying that specific gallery, the server queries the database and renders the unescaped malicious payload directly into the DOM.\nBecause the payload executes in the context of the victim's session, the attacker can leverage the browser's access to perform unauthorized actions via the WordPress REST API or other site functionality. If an administrator views the gallery, the payload could be used to create new administrative users, inject backdoors into themes, or exfiltrate sensitive site data.\nThe vulnerability affects all versions of the Robo Gallery plugin prior to 5.2.6. It is a persistent XSS, meaning the payload remains active in the database until the data is manually purged or the plugin is updated to a version that implements proper output encoding.\nSuccessful exploitation requires the attacker to have at least 'Author' role privileges, which are native to the WordPress environment. This effectively bypasses standard web application firewalls that may focus on external inputs, as the traffic originates from authenticated backend interaction."
}
CVE-2026-81154: Robo Gallery Stored XSS (MEDIUM Severity, CVSS: 6.8) | Sceawere