SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-15236

HIGH · CVSS 7.5 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

The Gallery for Google Photos WordPress plugin prior to version 1.2.1 is vulnerable due to improper access controls, which expose third-party OAuth credentials, including persistent access and refresh tokens, to unauthenticated users. This flaw can lead to long-term account compromise for users connected to the plugin. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential security risks.

CVE
CVE-2026-15236
Severity
HIGH
CVSS
7.5
EPSS
0.28%
WordPress

Original NVD Description

The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of the linked account.