CVE · Medium

CVE-2022-45841 — Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-45841 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.11 Missing Authorization Medium 5.4 < 3.2.11 3.2.11 2022-12-12

CVE-2022-45841

The Robo Gallery plugin for WordPress through version 3.2.9 contains authorization bypass vulnerabilities in multiple AJAX functions that fail to validate user capabilities, allowing authenticated subscribers and higher-level users to perform unauthorized actions including article creation, post enumeration, addon management, and gallery metrics manipulation. Several of these vulnerable AJAX functions additionally lack CSRF protection mechanisms, compounding the security risk.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.