PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14290 Embed Google Photos album CVE debrief

The Embed Google Photos album WordPress plugin through 2.2.1 has a stored cross-site scripting vulnerability. Users with the Contributor role or above can inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the affected post. This vulnerability allows for unauthorized content injection and can lead to medium-priority defensive actions being recommended due to its medium CVSS score of 6.8. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations. Evidence from the NVD and WPScan indicates a vulnerability in the Embed Google Photos album WordPress plugin, but detailed information about the vulnerability and affected versions is limited.

Vendor
Embed Google Photos album
Product
WordPress plugin
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-14
Original CVE updated
2026-08-26
Advisory published
2026-08-14
Advisory updated
2026-08-26

Who should care

Users of the Embed Google Photos album WordPress plugin, especially those with the Contributor role or above, and administrators of WordPress sites using this plugin should be aware of this vulnerability and take defensive actions to prevent unauthorized content injection and protect against stored cross-site scripting (XSS) attacks.

Technical summary

The Embed Google Photos album WordPress plugin through 2.2.1 does not properly escape shortcode attribute values, allowing for stored cross-site scripting (XSS) attacks. Users with Contributor or higher roles can inject malicious JavaScript, which can be executed in the browsers of users viewing affected posts, including administrators. This vulnerability has a medium CVSS score of 6.8, indicating medium-priority defensive actions are recommended.

Defensive priority

Medium-priority defensive actions are recommended due to the medium CVSS score of 6.8.

Recommended defensive actions

  • Apply the latest patch for the Embed Google Photos album WordPress plugin.
  • Restrict user roles and capabilities to prevent unauthorized content injection.
  • Monitor for suspicious activity and implement a web application firewall.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

Evidence from the NVD and WPScan indicates a vulnerability in the Embed Google Photos album WordPress plugin. However, detailed information about the vulnerability and affected versions is limited. The vulnerability allows users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the affected post. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-14290 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-14290

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-14290 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14290

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.