Sceawere
Vulnerability Detail
CVE-2026-81154UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Robo Gallery Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Robo Gallery
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape image alt text before outputting it in one of its gallery layouts, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected gallery, including administrators.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-10-11T07:17:24.267Z",
"pubdate": "2026-10-11T07:17:24.267Z",
"executiveSummary": "The Robo Gallery WordPress plugin, specifically versions prior to 5.2.6, contains a Stored Cross-Site Scripting (XSS) vulnerability.\nThis flaw arises from the improper sanitization and escaping of image alt text attributes before they are rendered in specific gallery layouts.\nThe vulnerability allows authenticated users with the Author role or higher to inject malicious JavaScript into the application, which is subsequently stored in the database.\nWhen an unsuspecting user—including administrative accounts—views the compromised gallery, the malicious payload executes within their browser session.\nThe impact of this vulnerability is significant, as it permits unauthorized actors to perform actions on behalf of the victim, potentially leading to full site compromise, account takeover, or session hijacking depending on the victim's privileges.\nExploitation is restricted to authenticated users with Author-level privileges or higher, meaning the attack surface is limited to internal users, though this represents a critical risk in multi-author environments.",
"technicalDetails": "The root cause of the vulnerability is an input validation failure where the Robo Gallery plugin fails to apply adequate sanitization and output escaping to the image alt text field.\nWordPress plugins are expected to use security functions such as esc_attr() when echoing metadata into HTML attributes. In this instance, the plugin directly embeds user-provided string input into the gallery markup without filtration.\nAn authenticated attacker with 'Author' privileges or higher can navigate to the gallery settings or image management interface and supply a crafted XSS payload within the alt text field of an image.\nWhen the gallery is rendered on the front end of the site, the browser interprets the malicious content as executable code rather than a static string. For instance, an attacker might inject a payload such as '><script>alert(document.cookie)</script>.\nThe attack flow follows a predictable pattern: first, the attacker injects the payload via the image meta fields. Second, the server stores this payload in the WordPress database associated with the image metadata. Third, when a victim navigates to a page displaying that specific gallery, the server queries the database and renders the unescaped malicious payload directly into the DOM.\nBecause the payload executes in the context of the victim's session, the attacker can leverage the browser's access to perform unauthorized actions via the WordPress REST API or other site functionality. If an administrator views the gallery, the payload could be used to create new administrative users, inject backdoors into themes, or exfiltrate sensitive site data.\nThe vulnerability affects all versions of the Robo Gallery plugin prior to 5.2.6. It is a persistent XSS, meaning the payload remains active in the database until the data is manually purged or the plugin is updated to a version that implements proper output encoding.\nSuccessful exploitation requires the attacker to have at least 'Author' role privileges, which are native to the WordPress environment. This effectively bypasses standard web application firewalls that may focus on external inputs, as the traffic originates from authenticated backend interaction."
}