CVE-2026-81155: Robo Gallery < 5.2.6 - Author+ Stored XSS via Gallery Search Label
The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape a gallery setting before outputting it on a frontend page, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing a gallery, including administrators.