Vulnerabilities / Robo Gallery / WPSEC-2026-0511
Robo Gallery <= 5.1.6 - Authenticated (Contributor+) Sensitive Information Exposure of Private and Draft Page Titles
Medium 4.3
CWE-200Fixed in 5.2.6
- ID
- WPSEC-2026-0511
- Plugin
- Robo Gallery – Photo & Image Slider (robo-gallery)
- Affected
- from 1.9.0 before 5.2.6
- Remediation
- Update to 5.2.6 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
- Attack surface
- Robo Gallery on WPSec AttackSurface
- Fix released
- Published
Description
The Robo Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.1.6 due to a missing post type and capability check in the AJAX action that renders the album hierarchy meta box. This makes it possible for authenticated attackers, with contributor-level access and above, to read the titles of arbitrary pages, galleries and other hierarchical posts, including private, draft and pending ones.
References
- https://wpsec.com/vuln/WPSEC-2026-0511/
- https://plugins.svn.wordpress.org/robo-gallery/tags/5.2.6/
- https://wordpress.org/plugins/robo-gallery/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS