PT-2026-67652 · WordPress · Nested Pages
CVE-2026-15233
·
Published
2026-08-04
·
Updated
2026-08-04
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Nested Pages WordPress plugin versions prior to 3.2.15
Description
Insufficient escaping of post titles before they are output into HTML attributes on an administrative listing screen allows users with the Editor role, or Contributor and Author roles when the plugin is enabled for the post type, to perform a Stored Cross-Site Scripting (XSS) attack. This enables the injection of arbitrary JavaScript that executes within the session of any higher-privileged user who views the affected screen.
Recommendations
Update the plugin to version 3.2.15 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nested Pages