WordPress Photo Gallery 1.2.8 Cross Site Scripting

WordPress Photo Gallery plugin version 1.2.8 suffers from a cross site scripting vulnerability.