Sceawere

Vulnerability Detail

CVE-2026-81156UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Robo Gallery Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
8h ago
Vendor
Unknown
Product
Robo Gallery
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape some of its gallery settings before outputting them on the gallery edit screen, allowing users with the Contributor role and above to store JavaScript that executes in the context of an administrator who opens the gallery for editing.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-10-11T07:17:24.493Z",
  "pubdate": "2026-10-11T07:17:24.493Z",
  "executiveSummary": "The Robo Gallery WordPress plugin, in versions prior to 5.2.6, contains a Stored Cross-Site Scripting (XSS) vulnerability within its administrative interface settings.\nThe vulnerability arises from the failure to properly sanitize and escape input fields within the plugin's gallery configuration menu.\nAn authenticated user with a minimum role of Contributor can inject malicious JavaScript payloads into these gallery settings.\nWhen an administrator accesses the gallery edit screen, the stored script executes within their browser context, potentially leading to unauthorized administrative actions, session hijacking, or account takeover.\nThis represents a significant security risk, as it allows lower-privileged users to escalate their impact by targeting high-privileged administrative accounts.\nExploitation requires active authentication and access to the gallery management interface, making the threat primarily internal to the WordPress installation.",
  "technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS). The root cause is the lack of server-side input sanitization and improper output encoding of gallery settings within the Robo Gallery WordPress plugin versions before 5.2.6.\nThe attack flow begins when an authenticated user (Contributor or higher) modifies gallery settings through the plugin's interface. Because the plugin does not validate or escape the provided input before storing it in the database, malicious scripts—typically in the form of <script> tags or event handlers—are persisted.\nWhen an administrator subsequently navigates to the gallery edit screen, the application retrieves the tainted data from the database and renders it directly into the HTML response without context-aware escaping. This causes the browser to execute the injected JavaScript under the administrator's security context.\nBecause the payload executes in the administrator's session, the attacker can leverage the browser's access to the WordPress backend to perform unauthorized actions. Examples include modifying site settings, creating new administrator accounts, injecting further malicious content into the site, or stealing session cookies.\nThe vulnerable component is the gallery configuration handler within the plugin's administrative settings module. The payload behavior is limited only by the capabilities of the injected JavaScript and the permissions of the targeted administrator's current session.\nThe vulnerability is restricted to authenticated users with sufficient privileges to access the gallery management tools. It does not require remote network access beyond the WordPress dashboard interface. The impact is significant as it effectively bypasses access control mechanisms by utilizing the administrator as a proxy for malicious activity."
}
CVE-2026-81156: Robo Gallery Stored XSS Vulnerability (MEDIUM Severity, CVSS: 6.8) | Sceawere