02/27/2017
February goes in the books as being the absolute most atrocious for website security. Massive increases in vulnerability exploits, malware injection attempts, even defacement campaigns. Yet another was announced today for NextGen Gallery. We don't actually like or recommend this plugin but it's got a ton of users - if you have this installed and are not on a maintenance plan, update immediately! (Virtual Webmaster maintenance clients who have this plugin have already been updated - you're safe!)
http://bit.ly/2lNcMUx
A vulnerability in NextGEN Gallery fixed in version 2.1.79 allows SQL injection due to unsanitized user input.