Junglewise Threat Intelligence

CVE-2026-14290: Embed Google Photos album plugin stored XSS in shortcode attribute

CVE-2026-14290 · Severity: medium · CVSS 6.8 · Published 2026-08-14

Executive brief

The Embed Google Photos album WordPress plugin through version 2.2.2 fails to properly escape user-supplied shortcode attributes before rendering them in HTML, enabling WordPress contributors to inject malicious JavaScript. When an administrator or other user views a post containing an attacker's crafted shortcode, the injected JavaScript executes in their browser with their permissions, potentially leading to account compromise or data theft.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in the plugin's shortcode handler. The vulnerable component fails to escape the "link" shortcode attribute before outputting it into an HTML data attribute (data-link). An attacker with Contributor role or higher can craft a shortcode with a malicious URL containing a double-quote character followed by an event handler attribute (e.g., onmouseover="alert()"), which breaks out of the data-link attribute and executes as JavaScript. No authentication bypass is required beyond WordPress Contributor access; the payload persists in the post content and executes every time any user (including administrators) views the post. No patch has been announced as of the advisory date.

Affected products

  • Embed Google Photos album Embed Google Photos album through 2.2.2

Timeline

  • 2026-08-11: disclosed: Publicly published on WPScan
  • 2026-08-14: advisory: Published in NVD

References