A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.
https://wpvulndb.com/vulnerabilities/9480
https://wordpress.org/plugins/photo-gallery/#developers