CVE-2026-81153
Robo Gallery < 5.2.6 - Author+ Stored XSS via Image Overlay Effect Meta
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape some of its image settings before outputting them in a gallery page, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the gallery, including administrators, even where the unfiltered_html capability is disallowed such as on multisite.
| Vendor | unknown |
| Product | robo gallery |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown robo gallery
Be the first to know when new unknown vulnerabilities affecting unknown robo gallery are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Robo Gallery
0 < 5.2.6
References
Credits
Kenneth Billones WPScan