Sceawere
Vulnerability Detail
CVE-2026-81156UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Robo Gallery Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Robo Gallery
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape some of its gallery settings before outputting them on the gallery edit screen, allowing users with the Contributor role and above to store JavaScript that executes in the context of an administrator who opens the gallery for editing.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-10-11T07:17:24.493Z",
"pubdate": "2026-10-11T07:17:24.493Z",
"executiveSummary": "The Robo Gallery WordPress plugin, in versions prior to 5.2.6, contains a Stored Cross-Site Scripting (XSS) vulnerability within its administrative interface settings.\nThe vulnerability arises from the failure to properly sanitize and escape input fields within the plugin's gallery configuration menu.\nAn authenticated user with a minimum role of Contributor can inject malicious JavaScript payloads into these gallery settings.\nWhen an administrator accesses the gallery edit screen, the stored script executes within their browser context, potentially leading to unauthorized administrative actions, session hijacking, or account takeover.\nThis represents a significant security risk, as it allows lower-privileged users to escalate their impact by targeting high-privileged administrative accounts.\nExploitation requires active authentication and access to the gallery management interface, making the threat primarily internal to the WordPress installation.",
"technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS). The root cause is the lack of server-side input sanitization and improper output encoding of gallery settings within the Robo Gallery WordPress plugin versions before 5.2.6.\nThe attack flow begins when an authenticated user (Contributor or higher) modifies gallery settings through the plugin's interface. Because the plugin does not validate or escape the provided input before storing it in the database, malicious scripts—typically in the form of <script> tags or event handlers—are persisted.\nWhen an administrator subsequently navigates to the gallery edit screen, the application retrieves the tainted data from the database and renders it directly into the HTML response without context-aware escaping. This causes the browser to execute the injected JavaScript under the administrator's security context.\nBecause the payload executes in the administrator's session, the attacker can leverage the browser's access to the WordPress backend to perform unauthorized actions. Examples include modifying site settings, creating new administrator accounts, injecting further malicious content into the site, or stealing session cookies.\nThe vulnerable component is the gallery configuration handler within the plugin's administrative settings module. The payload behavior is limited only by the capabilities of the injected JavaScript and the permissions of the targeted administrator's current session.\nThe vulnerability is restricted to authenticated users with sufficient privileges to access the gallery management tools. It does not require remote network access beyond the WordPress dashboard interface. The impact is significant as it effectively bypasses access control mechanisms by utilizing the administrator as a proxy for malicious activity."
}