CVE · Medium

CVE-2025-47521 — Robo Gallery – Photo & Image Slider [robo-gallery] < 5.0.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-47521 Robo Gallery – Photo & Image Slider [robo-gallery] < 5.0.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 5.0.3 5.0.3 2025-05-07

CVE-2025-47521

A Stored Cross-Site Scripting vulnerability exists in the Robo Gallery plugin for WordPress, affecting versions up to 5.0.2. The issue arises from inadequate filtering of input data and insufficient protection against malicious code injection during output rendering. This weakness allows authorized attackers with elevated access rights to embed executable scripts on targeted pages, which will be executed when users visit those pages.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.