Impact
The Robo Gallery plugin contains a DOM‑based Cross‑Site Scripting (XSS) flaw. The plugin fails to neutralize user input during page generation, allowing an attacker to inject malicious JavaScript that executes in the victim’s browser. This flaw can be used to steal credentials, hijack sessions, or perform arbitrary actions within the user’s session, representing a classic CWE‑79 weakness.
Affected Systems
All installations of the robosoft Robo Gallery WordPress plugin, from the earliest releases through version 5.1.2, are potentially vulnerable. Users running any version less than or equal to 5.1.2 are affected. The vendor is Robosoft and the product is the Robo Gallery plugin.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is reported as less than 1 %, suggesting a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can craft a malicious URL or input that is rendered into the DOM, and when a victim visits the link or submits the input, the injected script runs without additional privileges.
OpenCVE Enrichment