SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the album parameter.
https://www.exploit-db.com/exploits/4993
https://exchange.xforce.ibmcloud.com/vulnerabilities/39964
https://euvd.enisa.europa.eu/vulnerability/EUVD-2008-0501