CVE · Medium

CVE-2024-22295 — Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.18

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-22295 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.18 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 3.2.18 3.2.18 2024-01-17

CVE-2024-22295

Robo Gallery versions before 3.2.18 contain a cross-site scripting vulnerability that could allow an attacker to inject malicious scripts into a website, which would then execute in visitors' browsers and potentially redirect users, display unwanted advertisements, or deliver other harmful HTML content. The flaw was discovered by Bryan Satyamulya and has been resolved in version 3.2.18 and later. WordPress site administrators using this plugin should update immediately to prevent exploitation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.