What is CVE-2026-15236?
The Gallery for Google Photos WordPress plugin before version 1.2.1 fails to properly restrict access to stored third-party OAuth credentials, allowing unauthenticated users to obtain persistent access and refresh tokens. This leads to potential long-term compromise of the linked Google account. Updating the plugin to version 1.2.1 or later is strongly recommended.
Azərbaycanca: The Gallery for Google Photos WordPress plaqininin 1.2.1-dən əvvəlki versiyalarında qeyd olunmuş OAuth tokenlərinə məhdudiyyətsiz giriş imkanı aşkarlanıb. Bu zəiflik autentifikasiya olunmamış istifadəçilərə bağlı Google hesabının Access Token və Refresh Token-ini əldə etməyə imkan verir, nəticədə hesab uzunmüddətli kompromatə məruz qala bilər. Plaqini ən azı 1.2.1 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Google
FAQ2
Which versions of the Gallery for Google Photos plugin are affected by this vulnerability?
All versions of the plugin before 1.2.1 are affected.
What data can an unauthenticated attacker obtain through this vulnerability?
The Access Token and Refresh Token of the linked Google account.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.