Robo Gallery, a popular WordPress plugin used for displaying photo galleries and sliders, contains a critical vulnerability, CVE-2024-10102. This flaw allows attackers to inject malicious JavaScript code into the plugin’s settings via a simple stored Cross-Site Scripting (XSS) attack. The vulnerability can be exploited by users with contributor privileges, enabling them to create a backdoor in the WordPress admin area. This backdoor can then be used to hijack admin accounts, potentially gaining full control of the website. With over 50,000 active installations, this vulnerability poses a significant risk to sites using Robo Gallery.
CVE-2024-10102 – Robo Gallery (Photo Gallery, Images, Slider in Rbs Image Gallery) – Stored XSS to JS Backdoor Creation – POC
![CVE-2024-10102 – Robo Gallery (Photo Gallery, Images, Slider in Rbs Image Gallery) – Stored XSS to JS Backdoor Creation – POC CVE-2024-10102 – Robo Gallery (Photo Gallery, Images, Slider in Rbs Image Gallery) – Stored XSS to JS Backdoor Creation – POC](https://research.cleantalk.org/wp-content/uploads/2023/10/New_1_not_safe-1.png)