AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-14290

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Embed Google Photos album plugin for WordPress versions up to 2.2.1 is vulnerable due to improper escaping of shortcode attribute values, enabling users with Contributor roles or higher to inject arbitrary JavaScript. This flaw allows the execution of malicious scripts in the browsers of any user, including administrators, who access the affected posts. WordPress site administrators and plugin maintainers should prioritize this vulnerability to mitigate potential cross-site scripting (XSS) attacks.

CVE
CVE-2026-14290
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
WordPress Java

Original NVD Description

The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the affected post.