The Gallery Bank – WordPress Photo Gallery plugin for WordPress is vulnerable to a type of malicious attack called SQL Injection. This issue affects versions up to, and including, 3.0.101. This vulnerability can be exploited by attackers who have editor-level permissions or higher. It allows them to inject additional SQL commands into existing queries, which can be used to access sensitive information from the database.