NextGEN Gallery is one f widely used WordPress plugins. As per the statastics available in WordPress plugin directory, this plugin was downloaded more than 1+ million times. That means, this plugin should be used on large number of WordPress installation. Researcher found a critical SQL injection vulnerability in NextGEN Gallery plugin. This vulnerability allows an