Impact
The vulnerability in Robosoft Robo Gallery is an improper neutralization of input that allows stored cross‑site scripting. An attacker can embed malicious JavaScript into gallery data, which will be rendered when the page is viewed. This can lead to defacement, credential theft, or session hijacking for users who view the compromised content.
Affected Systems
WordPress installations running Robo Gallery version 5.0.2 or earlier are affected. The vendor is Robosoft. No further sub‑version detail is provided, but all releases up to and including 5.0.2 contain the flaw.
Risk and Exploitability
The CVSS score of 5.9 denotes a medium impact, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the gallery’s data entry interface, requiring the attacker to insert a script that will be stored and later rendered to site visitors.
OpenCVE Enrichment
EUVD