The Envira Photo Gallery plugin for WordPress is not secure in versions up to 1.8.4.6. This means that an unauthenticated person can inject malicious code into a page if they can get a user to click a link. This malicious code can be used to gain access to the website or the user’s information.