WordPress and WordPress plugin are both products of the WordPress Foundation. WordPress is a set of blogging platforms developed using the PHP language. WordPress plugin is an application plugin. WordPress Gmedia Photo Gallerys plugin version 1.20.0 before version 1.20.0 has a cross-site scripting vulnerability, which stems from a failure to clean up and escape Album’s name. An attacker could exploit this vulnerability to execute JavaScript code on the client side.