CVE-2026-14290
Received Received - Intake

Stored XSS in Embed Google Photos Album WordPress Plugin

Vulnerability report for CVE-2026-14290, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-14

Last updated on: 2026-08-14

Assigner: WPScan

Description

The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the affected post.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-14
Last Modified
2026-08-14
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored Cross-Site Scripting (XSS) flaw in the Embed Google Photos album WordPress plugin version 2.2.1 and below. It occurs because the plugin does not properly escape a shortcode attribute value before outputting it in an HTML attribute. This allows users with the Contributor role or higher to inject arbitrary JavaScript code into posts.

Detection Guidance

Check for the presence of the Embed Google Photos album WordPress plugin version 2.2.1 or below. Inspect posts or pages using the plugin's shortcode for unsanitized user input in attributes. Look for unexpected JavaScript code in rendered HTML output.

Impact Analysis

The injected JavaScript can execute in the browsers of any user who views the affected post, including administrators. This could lead to unauthorized actions, data theft, or session hijacking. Attackers could steal sensitive information or take control of user accounts.

Compliance Impact

This vulnerability could lead to data breaches, which may violate GDPR and HIPAA requirements for protecting user data. Organizations could face fines or legal penalties if user data is compromised due to this flaw.

Mitigation Strategies

Disable or uninstall the Embed Google Photos album WordPress plugin immediately. Monitor for unauthorized changes to posts or pages. Apply any future updates or patches released by the plugin developer. Restrict user roles to minimize exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14290. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart