CyberRota Analysis
AI-GeneratedThe Embed Google Photos album plugin for WordPress versions up to 2.2.1 is vulnerable due to improper escaping of shortcode attribute values, enabling users with Contributor roles or higher to inject arbitrary JavaScript. This flaw allows the execution of malicious scripts in the browsers of any user, including administrators, who access the affected posts. WordPress site administrators and plugin maintainers should prioritize this vulnerability to mitigate potential cross-site scripting (XSS) attacks.
Original NVD Description
The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the affected post.