PatchSiren

Robo Gallery CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Robo Gallery CVE published 2026-04-08

CVE-2026-4300

The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Loading Label' setting in all versions up to, and including, 5.1.3. This vulnerability allows authenticated attackers with Author-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a page containing the gallery shortcode. The plugin uses a custom `|***...***|` [truncated]