Plugin Vulnerability Hub
Plugin 18 known issues Latest disclosed Apr 07, 2026

Robo Gallery – Photo & Image Slider Vulnerabilities

Review known vulnerability records for the WordPress plugin Robo Gallery – Photo & Image Slider (`robo-gallery`), including severity, CVE references, affected versions, and patch status.

Known Records
18
High or Critical
3
Linked CVEs
17
Last Updated
Apr 07, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Robo Gallery – Photo & Image Slider so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
18 records include a published patch path.
Severity Mix
1 critical and 2 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Robo Gallery – Photo & Image Slider

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-4300
Robo Gallery <= 5.1.3 - Authenticated (Author+) Stored Cross-Site Scripting via 'Loading Label' Setting

The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Loading Label' setting in all versions up to, and including, 5.1.3. The plugin uses a custom `|***...***|` marker pattern in its `fixJsFunction()` method to embed raw JavaScript function r...

Published
Apr 07, 2026
Patched Release
5.1.4
Affected Versions
Versions up to 5.1.3
Next Step
Update to 5.1.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-47521
Robo Gallery <= 5.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to...

Published
May 07, 2025
Patched Release
5.0.3
Affected Versions
Versions up to 5.0.2
Next Step
Update to 5.0.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-10144
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.21 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery Settings in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping. This makes it possible for unauth...

Published
Mar 11, 2025
Patched Release
3.2.22
Affected Versions
Versions up to 3.2.21
Next Step
Update to 3.2.22 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-13384
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.23 - Authenticated (Admin+) Stored Cross-Site Scripting

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.23 due to insufficient input sanitization and output escaping. This makes it possible for authenti...

Published
Mar 03, 2025
Patched Release
3.2.24
Affected Versions
Versions up to 3.2.23
Next Step
Update to 3.2.24 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-10102
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.21 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery Settings in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping. This makes it possible for unauth...

Published
Dec 17, 2024
Patched Release
3.2.22
Affected Versions
Versions up to 3.2.21
Next Step
Update to 3.2.22 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-49696
Robo Gallery <= 3.2.21 - Authenticated (Author+) Stored Cross-Site Scripting

The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to injec...

Published
Oct 21, 2024
Patched Release
3.2.22
Affected Versions
Versions up to 3.2.21
Next Step
Update to 3.2.22 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-8431
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Private Gallery Title Disclosure

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated a...

Published
Oct 07, 2024
Patched Release
3.2.22
Affected Versions
Versions up to 3.2.21
Next Step
Update to 3.2.22 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3896
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Title

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the Gallery title field in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible...

Published
Jul 24, 2024
Patched Release
3.2.20
Affected Versions
Versions up to 3.2.19
Next Step
Update to 3.2.20 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3894
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.19 - Authenticated (Author+) Stored Cross-Site Scripting via Image Title

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an Image Title in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible for authenti...

Published
Jun 18, 2024
Patched Release
3.2.20
Affected Versions
Versions up to 3.2.19
Next Step
Update to 3.2.20 or newer if supported.
Plugin High Patched: Yes CVE-2024-5343
Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.19 - Cross-Site Request Forgery to Post Creation and Limited Data Loss

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.19. This is due to missing or incorrect nonce validation on the 'rbs_ajax_create_article' and 'rbs_ajax_reset_views' f...

Published
Jun 18, 2024
Patched Release
3.2.20
Affected Versions
Versions up to 3.2.19
Next Step
Update to 3.2.20 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-34382
Robo Gallery <= 3.2.18 - Unauthenticated Information Exposure

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.18. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Published
May 03, 2024
Patched Release
3.2.19
Affected Versions
Versions up to 3.2.18
Next Step
Update to 3.2.19 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-22295
Robo Gallery <= 3.2.17 - Authenticated (Author+) Stored Cross-Site Scripting

The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to injec...

Published
Jan 17, 2024
Patched Release
3.2.18
Affected Versions
Versions up to 3.2.17
Next Step
Update to 3.2.18 or newer if supported.