What is CVE-2026-14290?
This vulnerability in the Embed Google Photos album plugin (up to 2.2.1) allows users with Contributor role or above to inject arbitrary JavaScript via an unescaped shortcode attribute, leading to Stored XSS. The malicious script executes in the browser of any user, including administrators, potentially compromising the site. Immediate plugin update is required.
Azərbaycanca: Bu zəiflik Embed Google Photos album pluginində (2.2.1-ə qədər) Contributor və yuxarı rol sahiblərinə qısa kod atributu vasitəsilə JavaScript injection etməyə imkan verir. Admin də daxil istənilən istifadəçinin brauzerində kod icrasına səbəb ola bilən Stored XSS riski yaradır. Plugin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
From which user role can CVE-2026-14290 be exploited in the Embed Google Photos album plugin?
This Stored XSS vulnerability can be exploited by users with Contributor role or above. They can inject arbitrary JavaScript via an unescaped shortcode attribute.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.