Junglewise Threat Intelligence

CVE-2026-4300: Robo Gallery Stored XSS in Loading Label setting

CVE-2026-4300 · Severity: medium · CVSS 6.4 · Published 2026-04-08

Executive brief

Robo Gallery is a popular WordPress plugin used to create and manage image galleries. A security flaw allows users with 'Author' level permissions or higher to inject malicious scripts into the gallery's 'Loading Label' setting. When other users or visitors view a page containing the affected gallery, these scripts will execute in their browser, potentially leading to unauthorized actions or data theft.

Technical details

The Robo Gallery plugin is vulnerable to Stored Cross-Site Scripting (XSS) due to an unsafe implementation of the `fixJsFunction()` method. This method uses a custom `|***...***|` marker pattern to convert JSON-encoded strings into raw JavaScript function references. While the 'Loading Label' field (stored as `rbs_gallery_LoadingWord`) is sanitized with `sanitize_text_field()`, this function only removes HTML tags and fails to strip the custom markers. An attacker with Author-level privileges can input a payload like `|***alert(1)***|`, which bypasses sanitization and is later rendered within an inline `<script>` tag on the frontend. This results in arbitrary JavaScript execution in the context of the victim's browser. The vulnerability is present in all versions up to and including 5.1.3.

Affected products

  • RoboSoft Robo Gallery Up to and including 5.1.3

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory

References