Sceawere

Vulnerability Detail

CVE-2026-81155UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Robo Gallery Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
8h ago
Vendor
Unknown
Product
Robo Gallery
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape a gallery setting before outputting it on a frontend page, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing a gallery, including administrators.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-10-11T07:17:24.387Z",
  "pubdate": "2026-10-11T07:17:24.387Z",
  "executiveSummary": "A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Robo Gallery WordPress plugin in all versions prior to 5.2.6. This security flaw stems from inadequate input sanitization and improper context-aware output escaping when processing gallery configuration settings. As a result, authenticated users possessing low-level managerial privileges, specifically the Author role or higher, can insert malicious scripts into gallery settings.\nWhen a frontend user or site administrator views a web page containing the affected gallery, the embedded malicious payload is rendered directly into the Document Object Model (DOM) and executed in the victim's browser context. The risk implications are severe: an attacker exploiting this vulnerability can execute arbitrary JavaScript commands on visitors, potentially hijacking administrator session cookies, stealing sensitive tokens, executing unauthorized administrative operations via cross-site request forgery or REST API calls, or redirecting users to malicious external domains. Exploitation requires authenticated access with at least Author-level permissions and successful rendering of the manipulated gallery on a publicly accessible or internally viewed page.",
  "technicalDetails": "The vulnerability manifests within the administrative settings management component of the Robo Gallery WordPress plugin prior to version 5.2.6. The root cause is a failure to enforce strict input sanitization policies when gallery settings are submitted and a concurrent failure to implement secure context-sensitive output escaping prior to rendering those settings on the frontend interface.\nDuring the administrative workflow, users with the Author role or above are granted permission to create, edit, and configure gallery instances. When an authorized attacker populates a gallery setting field with an arbitrary JavaScript vector—such as script tags or event handlers—the application persists this raw string directly into the WordPress database without stripping unsafe HTML tags or applying appropriate sanitization functions.\nThe complete attack flow proceeds through the following sequential stages:\n1. Authentication and Access: The attacker authenticates to the WordPress management dashboard using valid credentials assigned to the Author role or higher.\n2. Payload Injection: The attacker navigates to the Robo Gallery interface and modifies a gallery configuration field, embedding a customized executable client-side payload.\n3. Persistence: The plugin processes the update request and commits the unsanitized payload into the backend storage repository.\n4. Vector Delivery: The compromised gallery is published or embedded into a post or page accessible to frontend visitors and system administrators.\n5. Execution Trigger: When a target visitor or administrator requests the page containing the gallery, the plugin fetches the stored configuration setting from the database and constructs the HTML response. Because the setting is rendered without proper HTML entity escaping, the raw payload is delivered directly inside the HTTP response body.\n6. Context Execution: The target browser interprets the injected code as executable content within the origin context of the WordPress site. If the victim holds Administrator privileges, the executed script operates with full administrative authority, allowing the payload to silently interact with WordPress REST API endpoints, create new superuser accounts, alter critical system configurations, or deploy further persistent backdoors."
}
CVE-2026-81155: Robo Gallery Stored XSS Vulnerability (MEDIUM Severity, CVSS: 6.8) | Sceawere