PT-2026-67064 · WordPress · Gallery For Google Photos
CVE-2026-15236
·
Published
2026-08-02
·
Updated
2026-08-02
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Gallery for Google Photos versions prior to 1.2.1
Description
This issue occurs when the plugin fails to properly restrict access to stored third-party OAuth credentials of the connected account. This flaw exposes persistent access and refresh tokens to unauthenticated users, which can lead to the long-term compromise of the linked account.
Recommendations
Update Gallery for Google Photos to version 1.2.1 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gallery For Google Photos