The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to a data security issue. This issue affects versions up to and including 2.52 and can be exploited by authenticated attackers. It allows them to determine the existence of certain directories in the admin/ajax.php, admin/news.php, and facebook.php files, by using the ‘dir’, ‘want2read’, and ‘f’ parameters respectively.