WordPress security by component
Nested Pages
Plugin description
Nested Pages is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 8.1.
Plugin slug:
nested-pagesLatest vulnerability
CVE-2026-15233: Nested Pages post titles permit administrator-facing stored XSS
Nested Pages before 3.2.15 outputs post titles into HTML attributes on its administrative listing screen without proper escaping. An Editor can store an attribute-breaking title; Contributor or Author access is also sufficient when Nested Pages is enabled for that post type. The script executes in the session of any higher-privileged user who views the listing. The public advisory does not disclose the affected attribute, listing renderer or title-save request fields.
| Safe version |
|
||
|---|---|---|---|
| Aug 04, 2026 |
CVE-2026-15233
Nested Pages post titles permit administrator-facing stored XSS
Nested Pages before 3.2.15 outputs post titles into HTML attributes on its administrative listing screen without proper escaping. An Editor can store an attribute-breaking title; Contributor or Author access is also sufficient when Nested Pages is enabled for that post type. The script executes in the session of any higher-privileged user who views the listing. The public advisory does not disclose the affected attribute, listing renderer or title-save request fields.
|
3.2.15 |
CVE4.8
NVDPending
|
| May 15, 2025 |
CVE-2024-8759
Nested Pages: Cross-site scripting
Nested Pages is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Mar 23, 2025 |
CVE-2025-0718
Nested Pages: Cross-site scripting
Nested Pages is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Jun 27, 2022 |
CVE-2022-1990
Nested Pages: Cross-site scripting
Nested Pages is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVEPending
NVD4.8
|
| Aug 30, 2021 |
CVE-2021-38343
Nested Pages: An open redirect
Nested Pages is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.7
NVD6.1
|
| Aug 30, 2021 |
CVE-2021-38342
Nested Pages: Cross-site request forgery
Nested Pages is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.1
NVD8.1
|