Access Control Flaw in Gallery for Google Photos Plugin from WordPress
CVE-2026-15236
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 August 2026
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2026-15236?
The Gallery for Google Photos plugin for WordPress prior to version 1.2.1 contains a significant access control vulnerability. This flaw allows unauthorized access to stored third-party OAuth credentials associated with the connected account. Consequently, unauthenticated users can retrieve persistent access and refresh tokens, leading to potential long-term compromise of the affected user's account. Proper access restrictions were not implemented for the critical OAuth tokens, exposing them to exploitation.
Affected Version(s)
Gallery for Google Photos 0 < 1.2.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.