WordPress Plugin Vulnerabilities

Gallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token Disclosure

Description

The plugin does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of the linked account.

Proof of Concept

Affects Plugins

Fixed in 1.2.1

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Original Researcher
Pablo González and Fran Ramírez
Submitter
Pablo González and Fran Ramírez
Verified
Yes

Timeline

Publicly Published
2026-07-23 (about 11 days ago)
Added
2026-07-23 (about 10 days ago)
Last Updated
2026-07-23 (about 10 days ago)

Other