CVE-2026-15236
Received Received - Intake

Gallery for Google Photos OAuth Token Exposure Vulnerability

Vulnerability report for CVE-2026-15236, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-02

Last updated on: 2026-08-02

Assigner: WPScan

Description

The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of the linked account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-02
Last Modified
2026-08-02
Generated
2026-08-02
AI Q&A
2026-08-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Gallery for Google Photos WordPress plugin before version 1.2.1 has an access control flaw. It exposes OAuth credentials like access and refresh tokens to unauthenticated users. This allows attackers to gain persistent access to the connected Google account without needing further authentication.

Detection Guidance

Check if the Gallery for Google Photos WordPress plugin version is below 1.2.1. Inspect network traffic for unauthorized access to OAuth tokens or exposed credentials. Review server logs for requests to plugin endpoints that may leak tokens.

Impact Analysis

If you use this plugin, an attacker could take over your connected Google account. They could access private photos, modify or delete content, and maintain long-term access even if you change passwords. Your website and linked services could be compromised.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and access controls. Organizations may face fines or legal consequences for failing to secure user data adequately.

Mitigation Strategies

Update the Gallery for Google Photos WordPress plugin to version 1.2.1 or later to fix the access restriction issue.

Review and revoke any exposed OAuth tokens for the connected Google account to prevent unauthorized access.

Check for unauthorized access or suspicious activity in the linked Google account and remove any unknown third-party applications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15236. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart