Cross-site scripting (XSS) vulnerability in includes/CatGridPost.php in the Category Grid View Gallery plugin 2.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ID parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/85395
http://www.securityfocus.com/bid/60905
http://seclists.org/bugtraq/2013/Jul/17
http://packetstormsecurity.com/files/122259/WordPress-Category-Grid-View-Gallery-XSS.html