Impact
The Embed Google Photos album WordPress plugin does not escape a shortcode attribute before embedding it in the output. This flaw allows any user with the Contributor role or higher to insert arbitrary JavaScript into a post. When other visitors, including administrators, view that post, the injected script runs in their browsers, which can lead to session hijacking, data theft, or other malicious actions performed on behalf of the user.
Affected Systems
The vulnerability affects the Embed Google Photos album WordPress plugin, with all releases up to and including version 2.2.1. Any WordPress installation using these versions is susceptible.
Risk and Exploitability
An attacker only needs Contributor‑level access, a common privilege for many users, to store the malicious code. There is no requirement to bypass authentication or exploit a separate vulnerability. Because the attack payload is stored in the content and executed for every visitor to the post, the potential for broad impact is high. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, but the inherent nature of stored XSS suggests a significant risk for sites with active contributors and valuable user data.
OpenCVE Enrichment