CVE-2026-15236
N/A
N/A
Summary
The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of the linked account.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Gallery for Google Photos | 0 < 1.2.1 | affected |
Weaknesses
- CWE-200 Information Exposure
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.