CyberRota Analysis
AI-GeneratedThe Gallery for Google Photos WordPress plugin prior to version 1.2.1 is vulnerable due to improper access controls, which expose third-party OAuth credentials, including persistent access and refresh tokens, to unauthenticated users. This flaw can lead to long-term account compromise for users connected to the plugin. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential security risks.
Original NVD Description
The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of the linked account.