PT-2026-103483 · WordPress · Nested Pages

CVE-2026-100512

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nested Pages versions prior to 3.3.3
Description Nested Pages is subject to a PHP Object Injection issue. This occurs when untrusted data is passed to the unserialize() function, allowing an attacker to inject malicious objects into the application state.
Recommendations Update Nested Pages to a version newer than 3.3.2.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100512

Affected Products

Nested Pages