The Gallery Bank – WordPress Photo Gallery Plugin for WordPress, versions before 2.0.20, is vulnerable to malicious code being injected into the user’s webpage. Attackers can use this vulnerability to inject malicious code into the page if they can get a user to click on a link. This occurs due to insufficient protection against malicious input and output.