---
id: CVE-2026-81156
title: >-
  The Robo Gallery  WordPress plugin before 5.2.6 does not sanitise and escape
  some of its gallery settings before outputting them on the gallery edit
  screen, allowing users with the Contributor role and above to store JavaScript
  that exec…
summary: >-
  The Robo Gallery  WordPress plugin before 5.2.6 does not sanitise and escape
  some of its gallery settings before outputting them on the gallery edit
  screen, allowing users with the Contributor role and above to store JavaScript
  that exec…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
published: '2026-10-11'
updated: '2026-10-11'
sourceUpdated: '2026-10-11T12:17:22.047'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81156'
references:
  - url: 'https://wpscan.com/vulnerability/e8c9aabb-a889-473b-b107-3aafb71a6956/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-10-11T08:44:24.714Z'
---

## Overview

The Robo Gallery  WordPress plugin before 5.2.6 does not sanitise and escape some of its gallery settings before outputting them on the gallery edit screen, allowing users with the Contributor role and above to store JavaScript that executes in the context of an administrator who opens the gallery for editing.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
