CVE-2026-15236Disclosure

LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-02: 3Patch / Workaround · 2026-08-02: 1Technical Details · 2026-08-02: 308-02
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-15236 Unauthenticated OAuth Credential Exposure in Gallery for Google Photos WordPress Plugin Before 1.2.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-15236

    Post summary

    The text announces CVE-2026-15236, an unauthenticated OAuth credential exposure in the Gallery for Google Photos WordPress plugin (before 1.2.1), but provides no proof‑of‑concept, exploit code, or mitigation guidance.

    00000125
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-15236 The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, e… https://www.cve.org/CVERecord?id=CVE-2026-15236 ----- Traducción: CVE-2026-15236 The… http://infoflow.cloud`

    Post summary

    The tweet informs that CVE-2026-15236 affects the Gallery for Google Photos WordPress plugin, allowing unrestricted access to stored OAuth credentials in versions prior to 1.2.1, and indicates that upgrading fixes the issue.

    0000034
    96 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-15236 The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, e… https://www.cve.org/CVERecord?id=CVE-2026-15236

    Post summary

    The CVE-2026-15236 disclosure indicates that the Gallery for Google Photos WordPress plugin (before 1.2.1) improperly restricts access to stored OAuth credentials, but no PoC, exploit, patch, or active exploitation details are provided.

    00000769
    57.9K followersView on X

Explore more