CVE-2026-15236: Gallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token Disclosure

Published Aug 2, 2026
·
Updated

The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of the linked account.

Affected Software

1 affected component
WordPress plugin Gallery for Google Photos<1.2.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Gallery for Google Photos (WordPress plugin) to a version that resolves this vulnerability.

    Fixed in 1.2.1
  2. Operational

    Revoke/rotate the connected account’s third-party OAuth tokens (persistent access and refresh tokens) that may have been exposed to unauthenticated users before upgrading the Gallery for Google Photos WordPress plugin to version 1.2.1.

Event History

Aug 2, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-15236?

The severity of CVE-2026-15236 is rated at 75, indicating a significant risk.

2

How do I fix CVE-2026-15236?

To fix CVE-2026-15236, update the Gallery for Google Photos plugin to version 1.2.1 or later.

3

What type of vulnerability is CVE-2026-15236?

CVE-2026-15236 is an information leakage vulnerability related to unauthenticated OAuth token disclosure.

4

Who is affected by CVE-2026-15236?

Users of the Gallery for Google Photos plugin for WordPress versions prior to 1.2.1 are affected by CVE-2026-15236.

5

What does CVE-2026-15236 expose?

CVE-2026-15236 exposes third-party OAuth credentials, including access and refresh tokens, to unauthenticated users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203