Executive brief
The Gallery for Google Photos WordPress plugin stores Google account credentials insecurely, making them accessible to anyone visiting a page with the gallery block without needing to log in. An attacker can steal the persistent refresh token, allowing indefinite unauthorized access to the victim's Google Photos account and potentially other connected Google services.
Technical details
The plugin improperly exposes OAuth tokens (access_token and refresh_token) in the HTML data attributes of the gallery block wrapper, readable by unauthenticated visitors. The vulnerability exists in two independent paths: (1) the data-info attribute on public pages contains the full token object as HTML-encoded JSON, and (2) a public AJAX handler (action=bpgpb_retrieve_access_token) returns the same token object when called with a nonce found in step 1. No authentication or valid session is required for either request. An attacker can extract the persistent refresh_token to maintain long-term unauthorized access to the connected Google account. The vulnerability is fixed in version 1.2.1.
Affected products
- WordPress Gallery for Google Photos before 1.2.1
Timeline
- 2026-07-23: disclosed
- 2026-07-23: patched: Fixed in version 1.2.1
- 2026-08-02: advisory