Vulnerabilities / Robo Gallery / WPSEC-2026-0513

Robo Gallery <= 5.1.6 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Reparenting and Reordering via Gallery Hierarchy Save

Medium 4.3 CWE-862Fixed in 5.2.6
ID
WPSEC-2026-0513
Plugin
Robo Gallery – Photo & Image Slider (robo-gallery)
Affected
from 1.9.0 before 5.2.6
Remediation
Update to 5.2.6 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-862
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
Robo Gallery on WPSec AttackSurface
Fix released
Published

Description

The Robo Gallery plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 5.1.6 due to a missing per-post capability check and post type validation in the AJAX handler that saves the gallery hierarchy. The handler accepted a client-supplied tree and called wp_update_post on every ID with only a generic edit_posts check. This makes it possible for authenticated attackers, with contributor-level access and above, to change the parent and menu order of arbitrary posts on the site, including posts they are not permitted to edit.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0