WordPress Plugin Vulnerabilities

Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Attribute

Description

The plugin does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the affected post.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
testoun
Submitter
testoun
Verified
Yes

Timeline

Publicly Published
2026-08-11 (about 4 days ago)
Added
2026-08-04 (about 11 days ago)
Last Updated
2026-08-04 (about 11 days ago)

Other