Full title: WordPress Photo Gallery 1.2.8 XSS / SQL Injection Vulnerabilities Category: web applications Platform: php WordPress Photo Gallery plugin version 1.2.8 suffers from a cross site scripting and remote SQL injection vulnerabilities # 0day.today @ http://0day.today/