CVE-2025-47521: WordPress Robo Gallery plugin <= 5.0.2 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery allows Stored XSS. This issue affects Robo Gallery: from n/a through 5.0.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery robo-gallery allows Stored XSS.This issue affects Robo Gallery: from n/a through <= 5.0.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47521?
CVE-2025-47521 is classified as a critical vulnerability due to its potential for Stored XSS attacks.
How do I fix CVE-2025-47521?
To mitigate CVE-2025-47521, upgrade Robo Gallery to version 5.0.3 or later, which addresses the vulnerability.
What versions of Robo Gallery are affected by CVE-2025-47521?
CVE-2025-47521 affects all versions of Robo Gallery from n/a through 5.0.2.
What type of vulnerability is CVE-2025-47521?
CVE-2025-47521 is an Improper Neutralization of Input During Web Page Generation, specifically a Stored Cross-site Scripting (XSS) vulnerability.
Can CVE-2025-47521 impact website security?
Yes, CVE-2025-47521 can significantly impact website security by allowing attackers to execute malicious scripts in the context of a user's session.