The unite-gallery-lite plugin prior to 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.
unitegallery unite gallery lite