PLUGIN SECURITY
Is Robo Gallery safe?
Robo Gallery is a powerful image gallery and photo gallery plugin with advanced features to create responsive galleries with a beautiful lightbox
What this plugin does
- Slug:
robo-gallery - Author: robosoft
- 40000+ active installs
- 86/100 rating (404 reviews on wordpress.org)
- 2474619 all-time downloads
- On WordPress.org since 2015-07-14
galleryimage galleryphoto galleryresponsive gallerywordpress gallery plugin
Maintenance status
- Latest known version: 5.1.5
- Last updated: 2026-05-27 10:01am GMT
- Tested up to WordPress: 7.0.4
Known vulnerabilities
19 known CVEs on file for Robo Gallery.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-32356 | Robo Gallery – Photo & Image Slider [robo-gallery] < 5.1.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 5.1.3 | 5.1.3 | 2026-02-14 | ✓ fixed in latest |
| CVE-2024-5647 | Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.23 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.2.23 | 3.2.23 | 2025-07-02 | ✓ fixed in latest |
| CVE-2025-47521 | Robo Gallery – Photo & Image Slider [robo-gallery] < 5.0.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 5.0.3 | 5.0.3 | 2025-05-07 | ✓ fixed in latest |
| CVE-2024-10144 | Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.22 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 3.2.22 | 3.2.22 | 2025-03-11 | ✓ fixed in latest |
| CVE-2024-13384 | Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.24 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 3.2.24 | 3.2.24 | 2025-03-03 | ✓ fixed in latest |
| CVE-2024-10102 | Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.22 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Low 2.7 | < 3.2.22 | 3.2.22 | 2024-12-17 | ✓ fixed in latest |
| CVE-2024-49696 | Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.22 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 3.2.22 | 3.2.22 | 2024-10-21 | ✓ fixed in latest |
| CVE-2024-8431 | Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.22 | Missing Authorization | Medium 4.3 | < 3.2.22 | 3.2.22 | 2024-10-07 | ✓ fixed in latest |
+ 18 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-3896 | Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.20 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.2.20 | 3.2.20 | 2024-07-24 | ✓ fixed in latest |
| CVE-2024-5343 | Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.20 | Cross-Site Request Forgery (CSRF) | High 8.8 | < 3.2.20 | 3.2.20 | 2024-06-18 | ✓ fixed in latest |
| CVE-2024-3894 | Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.20 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.2.20 | 3.2.20 | 2024-06-18 | ✓ fixed in latest |
| CVE-2024-34382 | Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.19 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.3 | < 3.2.19 | 3.2.19 | 2024-05-03 | ✓ fixed in latest |
| CVE-2024-22295 | Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.18 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 3.2.18 | 3.2.18 | 2024-01-17 | ✓ fixed in latest |
| CVE-2023-3499 | Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.16 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 3.2.16 | 3.2.16 | 2023-08-15 | ✓ fixed in latest |
| CVE-2023-27620 | Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.13 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.2.13 | 3.2.13 | 2023-03-13 | ✓ fixed in latest |
| CVE-2022-45804 | Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.11 | Cross-Site Request Forgery (CSRF) | Medium 5.4 | < 3.2.11 | 3.2.11 | 2023-02-02 | ✓ fixed in latest |
| CVE-2023-24414 | Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.12 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 3.2.12 | 3.2.12 | 2023-01-30 | ✓ fixed in latest |
| CVE-2022-45841 | Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.11 | Missing Authorization | Medium 5.4 | < 3.2.11 | 3.2.11 | 2022-12-12 | ✓ fixed in latest |
| — | Robo Gallery – Photo & Image Slider [robo-gallery] < 2.0.17 | — | Unknown | < 2.0.17 | 2.0.17 | 2017-04-12 | ✓ fixed in latest |
| — | Robo Gallery – Photo & Image Slider [robo-gallery] < 2.0.15 | — | Unknown | < 2.0.15 | 2.0.15 | 2016-04-12 | ✓ fixed in latest |
| — | Robo Gallery – Photo & Image Slider [robo-gallery] < 2.0.15 | — | Unknown | < 2.0.15 | 2.0.15 | 2016-04-12 | ✓ fixed in latest |
| — | Robo Gallery – Photo & Image Slider [robo-gallery] < 5.1.4 | — | Medium 6.4 | < 5.1.4 | 5.1.4 | 0000-00-00 | ✓ fixed in latest |
| — | Robo Gallery – Photo & Image Slider [robo-gallery] < 2.0.15 | — | Unknown | < 2.0.15 | 2.0.15 | — | ✓ fixed in latest |
| — | Robo Gallery <= 2.0.14 - Remote Code Execution | — | Unknown | < 2.0.15 | 2.0.15 | — | ✓ fixed in latest |
| CVE-2024-5647 | Magnific Popups JavaScript Library < 1.2.0 - Contributor+ Stored XSS | — | Unknown | < 3.2.23 | 3.2.23 | — | ✓ fixed in latest |
| CVE-2026-4300 | Robo Gallery < 5.1.4 - Authenticated (Author+) Stored Cross-Site Scripting via 'Loading Label' Setting | — | Unknown | < 5.1.4 | 5.1.4 | — | ✓ fixed in latest |
How to fix it
Keep Robo Gallery updated — 5.1.5 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Smart Slider 3 — 800000+ active installs — 98/100 (1123) — max PHP <8.0
- Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider — 500000+ active installs — 92/100 (738) — max PHP 8.4
- Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery — 300000+ active installs — 86/100 (4339) — max PHP 8.4
- Firelight Lightbox — 200000+ active installs — 96/100 (357) — max PHP 8.4
- Photo Gallery by 10Web – Mobile-Friendly Image Gallery — 100000+ active installs — 90/100 (1581)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.