
CVE-2026-14290 The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users… https://www.cve.org/CVERecord?id=CVE-2026-14290
Post summary
The Embed Google Photos album WordPress plugin before version 2.2.1 has a vulnerability where it fails to escape a shortcode attribute value prior to outputting it in an HTML attribute, potentially enabling injection attacks.
