Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-14290— Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Attribute

Quick assessment

Affected
Unknown Embed Google Photos album
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Embed Google Photos album WordPress 插件(版本 2.2.1 及之前版本)在将短代码属性值输出到 HTML 属性中之前,未进行适当的转义处理,导致拥有“贡献者”或更高权限的用户可以注入任意 JavaScript 代码。任何查看受影响帖子的用户(包括管理员)的浏览器都会执行这些恶意脚本。

AI Predicted 6.1 Difficulty: Easy EPSS 0.43% · P35

Affected Version Matrix 1

VendorProduct Version RangeStatus
Unknown Embed Google Photos album ≤ 2.2.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-14290

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Attribute
Source: CVE Program / CVE List V5
Vulnerability Description
The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the affected post.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Embed Google Photos album 0 ~ 2.2.1 -

II. Public POCs for CVE-2026-14290

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-14290

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-14290 (1)

Same Patch Batch · Unknown · 2026-08-14 · 4 CVEs total

CVE-2026-15205 Paymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Callback Pixel L
CVE-2026-16739 Epeken All Kurir <= 2.1.4 - Unauthenticated Order Payment Confirmation Forgery
CVE-2026-18039 Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom P

IV. Related Vulnerabilities

V. Comments for CVE-2026-14290

No comments yet


Leave a comment