CVE-2026-14290: Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Attribute
The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the affected post.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14290?
CVE-2026-14290 has a risk score of 43, indicating a moderate severity level.
How do I fix CVE-2026-14290?
To fix CVE-2026-14290, update the Embed Google Photos Album Easily plugin to version 2.2.2 or later.
What type of vulnerability is CVE-2026-14290?
CVE-2026-14290 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-14290?
Users with the Contributor role or above on WordPress sites utilizing versions <= 2.2.1 of the plugin are affected.
What could be the impact of CVE-2026-14290?
The vulnerability allows attackers to inject arbitrary JavaScript that executes in the browsers of visitors, potentially compromising user data.