---
id: CVE-2026-81154
title: >-
  The Robo Gallery  WordPress plugin before 5.2.6 does not sanitise and escape
  image alt text before outputting it in one of its gallery layouts, allowing
  users with the Author role and above to perform Stored Cross-Site Scripting
  attacks …
summary: >-
  The Robo Gallery  WordPress plugin before 5.2.6 does not sanitise and escape
  image alt text before outputting it in one of its gallery layouts, allowing
  users with the Author role and above to perform Stored Cross-Site Scripting
  attacks …
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
published: '2026-10-11'
updated: '2026-10-11'
sourceUpdated: '2026-10-11T12:17:21.747'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81154'
references:
  - url: 'https://wpscan.com/vulnerability/c41c6bdc-a877-4012-9398-0fcdcc55c5a9/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-10-11T08:44:24.714Z'
---

## Overview

The Robo Gallery  WordPress plugin before 5.2.6 does not sanitise and escape image alt text before outputting it in one of its gallery layouts, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected gallery, including administrators.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
