The Visual Portfolio, Photo Gallery & Post Grid plugin for WordPress has a security issue where attackers can inject harmful code through the ‘title_tag’ parameter. This can happen in all versions up to 3.3.2 because the plugin does not properly clean the input and output. This means that malicious code can be added to pages and executed when a user visits that page.