Vulnerabilities / Robo Gallery / WPSEC-2026-0512
Robo Gallery <= 5.1.6 - Authenticated (Contributor+) Insecure Direct Object Reference to Gallery Cloning
Medium 5.4
CWE-639Fixed in 5.2.6
- ID
- WPSEC-2026-0512
- Plugin
- Robo Gallery – Photo & Image Slider (robo-gallery)
- Affected
- from 3.0.0 before 5.2.6
- Remediation
- Update to 5.2.6 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Weakness
- CWE-639
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
- Attack surface
- Robo Gallery on WPSec AttackSurface
- Fix released
- Published
Description
The Robo Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.6 due to the gallery clone action relying on a shared nonce and only a generic edit_posts check, without verifying that the user can edit the source gallery. This makes it possible for authenticated attackers, with contributor-level access and above, to clone any gallery, including other users' private or password-protected galleries along with all of their settings and images, and to have the copy keep a published status.
References
- https://wpsec.com/vuln/WPSEC-2026-0512/
- https://plugins.svn.wordpress.org/robo-gallery/tags/5.2.6/
- https://wordpress.org/plugins/robo-gallery/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS