A cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.
View the template here CVE-2011-4624.yaml
References:
http://www.openwall.com/lists/oss-security/2011/12/23/2