Vulnerabilities / Robo Gallery / WPSEC-2026-0511

Robo Gallery <= 5.1.6 - Authenticated (Contributor+) Sensitive Information Exposure of Private and Draft Page Titles

Medium 4.3 CWE-200Fixed in 5.2.6
ID
WPSEC-2026-0511
Plugin
Robo Gallery – Photo & Image Slider (robo-gallery)
Affected
from 1.9.0 before 5.2.6
Remediation
Update to 5.2.6 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-200
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
Robo Gallery on WPSec AttackSurface
Fix released
Published

Description

The Robo Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.1.6 due to a missing post type and capability check in the AJAX action that renders the album hierarchy meta box. This makes it possible for authenticated attackers, with contributor-level access and above, to read the titles of arbitrary pages, galleries and other hierarchical posts, including private, draft and pending ones.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0