CVE-2026-14290

The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the affected post.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-14 06:16

Updated : 2026-08-26 16:30


NVD link : CVE-2026-14290

Mitre link : CVE-2026-14290

CVE.ORG link : CVE-2026-14290


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')