The WP Easy Gallery plugin for WordPress has a security vulnerability that allows hackers to access sensitive information from the database. This occurs when the ‘key’ parameter is used in the plugin, and it affects all versions up to 4.8.5. This vulnerability is due to inadequate preparation and escaping of user-supplied input in the SQL query. As a result, attackers with Contributor-level access or higher can add their own malicious SQL queries to the existing ones and retrieve sensitive information.