The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape a gallery setting before outputting it on a frontend page, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing a gallery, including administrators.
https://wpscan.com/vulnerability/e6b574c6-1999-4318-a9aa-9529aeceeb8b/