CVE-2026-32356
The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-47521
The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-10144
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery Settings in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-13384
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-10102
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery Settings in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-49696
The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-8431
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve private post titles.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-3896
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the Gallery title field in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
+ 16 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-5343
|
Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.20 |
Falsificación de petición en sitios cruzados (CSRF) |
Alta
8,8
|
< 3.2.20
|
3.2.20 |
2024-06-18 |
—
|
|
CVE-2024-3894
|
Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.20 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 3.2.20
|
3.2.20 |
2024-06-18 |
—
|
|
CVE-2024-34382
|
Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.19 |
Exposición de información sensible a un actor no autorizado |
Media
5,3
|
< 3.2.19
|
3.2.19 |
2024-05-03 |
—
|
|
CVE-2024-22295
|
Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.18 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,9
|
< 3.2.18
|
3.2.18 |
2024-01-17 |
—
|
|
CVE-2023-3499
|
Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.16 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 3.2.16
|
3.2.16 |
2023-08-15 |
—
|
|
CVE-2023-27620
|
Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.13 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 3.2.13
|
3.2.13 |
2023-03-13 |
—
|
|
CVE-2022-45804
|
Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.11 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
5,4
|
< 3.2.11
|
3.2.11 |
2023-02-02 |
—
|
|
CVE-2023-24414
|
Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.12 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 3.2.12
|
3.2.12 |
2023-01-30 |
—
|
|
CVE-2022-45841
|
Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.11 |
Falta de control de autorización |
Media
5,4
|
< 3.2.11
|
3.2.11 |
2022-12-14 |
—
|
|
—
|
Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.11 |
— |
Desconocido
|
< 3.2.11
|
3.2.11 |
2022-12-12 |
—
|
|
—
|
Robo Gallery – Photo & Image Slider [robo-gallery] < 2.0.17 |
— |
Desconocido
|
< 2.0.17
|
2.0.17 |
2017-04-12 |
—
|
|
—
|
Robo Gallery – Photo & Image Slider [robo-gallery] < 2.0.15 |
— |
Desconocido
|
< 2.0.15
|
2.0.15 |
2016-04-12 |
—
|
|
—
|
Robo Gallery – Photo & Image Slider [robo-gallery] < 2.0.15 |
— |
Desconocido
|
< 2.0.15
|
2.0.15 |
2016-04-12 |
—
|
|
—
|
Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.23 |
— |
Media
6,4
|
< 3.2.23
|
3.2.23 |
0000-00-00 |
—
|
|
CVE-2026-4300
|
Robo Gallery – Photo & Image Slider [robo-gallery] < 5.1.4 |
— |
Media
6,4
|
< 5.1.4
|
5.1.4 |
0000-00-00 |
—
|
|
—
|
Robo Gallery – Photo & Image Slider [robo-gallery] < 2.0.15 |
— |
Desconocido
|
< 2.0.15
|
2.0.15 |
— |
—
|
CVE-2024-5343
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.19. This is due to missing or incorrect nonce validation on the 'rbs_ajax_create_article' and 'rbs_ajax_reset_views' functions. This makes it possible for unauthenticated attackers to create new posts and reset gallery view counts via a forged request granted they can trick a Contributor+ level user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-3894
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an Image Title in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-34382
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.18. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-22295
Update the WordPress Robo Gallery plugin to the latest available version (at least 3.2.18).
Bryan Satyamulya discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Robo Gallery Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.2.18.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-3499
The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-27620
Update the WordPress Robo Gallery plugin to the latest available version (at least 3.2.13).
Rafshanzani Suhada discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Robo Gallery Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.2.13.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2022-45804
Update the WordPress Robo Gallery plugin to the latest available version (at least 3.2.11).
Lana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Robo Gallery Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has been fixed in version 3.2.11.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-24414
No patched version is available. No reply from the vendor for a long time.
thiennv discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Robo Gallery Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has not been known to be fixed yet.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2022-45841
Update the WordPress Robo Gallery plugin to the latest available version (at least 3.2.11).
Tien Nguyen Anh discovered and reported this Broken Access Control vulnerability in WordPress Robo Gallery Plugin. This vulnerability has been fixed in version 3.2.11.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.11
The Robo Gallery plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 3.2.9. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to create articles, list posts, activate and deactivate addons and reset gallery view counts. Furthermore, several of these AJAX actions were missing Cross-Site Request Forgery Protection.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Robo Gallery – Photo & Image Slider [robo-gallery] < 2.0.17
WordPress Robo Gallery plugin Privilege Escalation Vulnerability exists in 2.0.15 version. It doesn't check if the current user is administrator so any logged in user can reset allery’s view count.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Robo Gallery – Photo & Image Slider [robo-gallery] < 2.0.15
This plugin is prone to a remote code execution vulnerability. It allows the attackers to execute own malicious php commands to compromise the web-application or connected dbms.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Robo Gallery – Photo & Image Slider [robo-gallery] < 2.0.15
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 via the vulnerable parameter 'function' that is supplied via the wp_ajax_rbs_gallery AJAX action. This allows unauthenticated attackers to execute code on the server.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.23
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-4300
The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Loading Label' setting in all versions up to, and including, 5.1.3. The plugin uses a custom `|***...***|` marker pattern in its `fixJsFunction()` method to embed raw JavaScript function references within JSON-encoded configuration objects. When a gallery's options are rendered on the frontend, `json_encode()` wraps all string values in double quotes. The `fixJsFunction()` method then strips the `"|***` and `***|"` sequences, effectively converting a JSON string value into raw JavaScript code. The Loading Label field (stored as `rbs_gallery_LoadingWord` post_meta) is an `rbstext` type field that is sanitized with `sanitize_text_field()` on save. While this strips HTML tags, it does not strip the `|***...***|` markers since they contain no HTML. When a user inputs `|***alert(document.domain)***|`, the value passes through sanitization intact, is stored in post_meta, and is later retrieved and output within an inline `<script>` tag via `renderMainBlock()` with the quote markers stripped — resulting in arbitrary JavaScript execution. The gallery post type uses `capability_type => 'post'`, allowing Author-level users to create galleries. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses a page containing the gallery shortcode.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Robo Gallery – Photo & Image Slider [robo-gallery] < 2.0.15
This is potentially a False Positive. Needs further investigation.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.