CVE-2026-15236: Gallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token Disclosure
The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of the linked account.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Gallery for Google Photos (WordPress plugin)to a version that resolves this vulnerability.Fixed in 1.2.1 - Operational
Revoke/rotate the connected account’s third-party OAuth tokens (persistent access and refresh tokens) that may have been exposed to unauthenticated users before upgrading the Gallery for Google Photos WordPress plugin to version 1.2.1.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15236?
The severity of CVE-2026-15236 is rated at 75, indicating a significant risk.
How do I fix CVE-2026-15236?
To fix CVE-2026-15236, update the Gallery for Google Photos plugin to version 1.2.1 or later.
What type of vulnerability is CVE-2026-15236?
CVE-2026-15236 is an information leakage vulnerability related to unauthenticated OAuth token disclosure.
Who is affected by CVE-2026-15236?
Users of the Gallery for Google Photos plugin for WordPress versions prior to 1.2.1 are affected by CVE-2026-15236.
What does CVE-2026-15236 expose?
CVE-2026-15236 exposes third-party OAuth credentials, including access and refresh tokens, to unauthenticated users.