The Robo Gallery plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting in versions up to 3.2.15. This type of attack makes it possible for someone with administrator-level permissions to inject malicious web scripts into pages on a website that will be executed whenever a user visits those pages. This vulnerability only affects multi-site installations and installations where a certain security setting (unfiltered_html) has been disabled.