The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress had a security issue which allowed attackers with administrator-level permissions to access sensitive information from the database. This vulnerability was caused by insufficient escaping of user supplied parameters and a lack of preparation of the existing SQL query in versions of the plugin up to and including 2.00.