JavaScript Injection Vulnerability in Embed Google Photos Album Plugin by WordPress
CVE-2026-14290
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 August 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-14290?
The Embed Google Photos album plugin for WordPress versions up to 2.2.1 is susceptible to a JavaScript injection vulnerability due to improper escaping of shortcode attribute values. This flaw enables authenticated users with a Contributor role or higher to inject malicious JavaScript code. When an affected post is viewed, the injected script runs in the browser of all users, including administrators, potentially leading to unauthorized actions and data exposure.
Affected Version(s)
Embed Google Photos album 0 <= 2.2.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.