The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the affected post.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-14 06:16
Updated : 2026-08-26 16:30
NVD link : CVE-2026-14290
Mitre link : CVE-2026-14290
CVE.ORG link : CVE-2026-14290
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
