Ghostwire

CVE-2026-81154: The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape image alt text before outputting it in one...

MEDIUM CVSS 0.0

Published: October 11, 2026 | Last Modified: October 11, 2026

Description

The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape image alt text before outputting it in one of its gallery layouts, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected gallery, including administrators.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References