WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Robo Gallery?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Robo Gallery — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: robo-gallery
  • 40000+ instalaciones activas

galleryimage galleryphoto galleryresponsive gallerywordpress gallery plugin

Estado de mantenimiento

Vulnerabilidades conocidas

18 CVEs conocidos registrados para Robo Gallery.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-32356 Robo Gallery – Photo & Image Slider [robo-gallery] < 5.1.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 5.1.3 5.1.3 2026-02-14
CVE-2025-47521 Robo Gallery – Photo & Image Slider [robo-gallery] < 5.0.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,9 < 5.0.3 5.0.3 2025-05-07
CVE-2024-10144 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.22 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 3.2.22 3.2.22 2025-03-11
CVE-2024-13384 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.24 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 3.2.24 3.2.24 2025-03-03
CVE-2024-10102 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.22 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Baja 2,7 < 3.2.22 3.2.22 2024-12-17
CVE-2024-49696 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.22 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,9 < 3.2.22 3.2.22 2024-10-21
CVE-2024-8431 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.22 Falta de control de autorización Media 4,3 < 3.2.22 3.2.22 2024-10-07
CVE-2024-3896 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.20 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.2.20 3.2.20 2024-07-24

CVE-2026-32356

The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-47521

The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-10144

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery Settings in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-13384

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-10102

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery Settings in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-49696

The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-8431

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve private post titles.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-3896

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the Gallery title field in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

+ 16 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-5343 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.20 Falsificación de petición en sitios cruzados (CSRF) Alta 8,8 < 3.2.20 3.2.20 2024-06-18
CVE-2024-3894 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.20 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 3.2.20 3.2.20 2024-06-18
CVE-2024-34382 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.19 Exposición de información sensible a un actor no autorizado Media 5,3 < 3.2.19 3.2.19 2024-05-03
CVE-2024-22295 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.18 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,9 < 3.2.18 3.2.18 2024-01-17
CVE-2023-3499 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.16 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 3.2.16 3.2.16 2023-08-15
CVE-2023-27620 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.13 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 3.2.13 3.2.13 2023-03-13
CVE-2022-45804 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.11 Falsificación de petición en sitios cruzados (CSRF) Media 5,4 < 3.2.11 3.2.11 2023-02-02
CVE-2023-24414 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.12 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 3.2.12 3.2.12 2023-01-30
CVE-2022-45841 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.11 Falta de control de autorización Media 5,4 < 3.2.11 3.2.11 2022-12-14
Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.11 Desconocido < 3.2.11 3.2.11 2022-12-12
Robo Gallery – Photo & Image Slider [robo-gallery] < 2.0.17 Desconocido < 2.0.17 2.0.17 2017-04-12
Robo Gallery – Photo & Image Slider [robo-gallery] < 2.0.15 Desconocido < 2.0.15 2.0.15 2016-04-12
Robo Gallery – Photo & Image Slider [robo-gallery] < 2.0.15 Desconocido < 2.0.15 2.0.15 2016-04-12
Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.23 Media 6,4 < 3.2.23 3.2.23 0000-00-00
CVE-2026-4300 Robo Gallery – Photo & Image Slider [robo-gallery] < 5.1.4 Media 6,4 < 5.1.4 5.1.4 0000-00-00
Robo Gallery – Photo & Image Slider [robo-gallery] < 2.0.15 Desconocido < 2.0.15 2.0.15

CVE-2024-5343

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.19. This is due to missing or incorrect nonce validation on the 'rbs_ajax_create_article' and 'rbs_ajax_reset_views' functions. This makes it possible for unauthenticated attackers to create new posts and reset gallery view counts via a forged request granted they can trick a Contributor+ level user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-3894

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an Image Title in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-34382

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.18. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-22295

Update the WordPress Robo Gallery plugin to the latest available version (at least 3.2.18). Bryan Satyamulya discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Robo Gallery Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.2.18. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-3499

The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-27620

Update the WordPress Robo Gallery plugin to the latest available version (at least 3.2.13). Rafshanzani Suhada discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Robo Gallery Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.2.13.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2022-45804

Update the WordPress Robo Gallery plugin to the latest available version (at least 3.2.11). Lana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Robo Gallery Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has been fixed in version 3.2.11.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-24414

No patched version is available. No reply from the vendor for a long time. thiennv discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Robo Gallery Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has not been known to be fixed yet.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2022-45841

Update the WordPress Robo Gallery plugin to the latest available version (at least 3.2.11). Tien Nguyen Anh discovered and reported this Broken Access Control vulnerability in WordPress Robo Gallery Plugin. This vulnerability has been fixed in version 3.2.11.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2026-4300

The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Loading Label' setting in all versions up to, and including, 5.1.3. The plugin uses a custom `|***...***|` marker pattern in its `fixJsFunction()` method to embed raw JavaScript function references within JSON-encoded configuration objects. When a gallery's options are rendered on the frontend, `json_encode()` wraps all string values in double quotes. The `fixJsFunction()` method then strips the `"|***` and `***|"` sequences, effectively converting a JSON string value into raw JavaScript code. The Loading Label field (stored as `rbs_gallery_LoadingWord` post_meta) is an `rbstext` type field that is sanitized with `sanitize_text_field()` on save. While this strips HTML tags, it does not strip the `|***...***|` markers since they contain no HTML. When a user inputs `|***alert(document.domain)***|`, the value passes through sanitization intact, is stored in post_meta, and is later retrieved and output within an inline `<script>` tag via `renderMainBlock()` with the quote markers stripped — resulting in arbitrary JavaScript execution. The gallery post type uses `capability_type => 'post'`, allowing Author-level users to create galleries. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses a page containing the gallery shortcode.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Cómo solucionarlo

Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.