Medium severity6.8NVD Advisory· Published Aug 14, 2026· Updated Aug 26, 2026
CVE-2026-14290
CVE-2026-14290
Description
The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the affected post.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=2.2.1
Patches
Vulnerability mechanics
References
1News mentions
2- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 10, 2026 to August 16, 2026)Wordfence Blog · Aug 21, 2026
- WordPress: 24 Plugin Flaws Including Critical Backdoors and Account Takeovers Disclosed TogetherVypr Intelligence · Aug 14, 2026