PT-2026-67652 · WordPress · Nested Pages

CVE-2026-15233

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nested Pages WordPress plugin versions prior to 3.2.15
Description Insufficient escaping of post titles before they are output into HTML attributes on an administrative listing screen allows users with the Editor role, or Contributor and Author roles when the plugin is enabled for the post type, to perform a Stored Cross-Site Scripting (XSS) attack. This enables the injection of arbitrary JavaScript that executes within the session of any higher-privileged user who views the affected screen.
Recommendations Update the plugin to version 3.2.15 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15233

Affected Products

Nested Pages