CVE-2026-15233
Nested Pages < 3.2.15 - Editor+ Stored XSS via Post Title
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing users with the Editor role (or Contributor/Author when the Nested Pages WordPress plugin before 3.2.15 is enabled for the post type) to inject arbitrary JavaScript that executes in the session of any higher-privileged user who views that screen.
| Vendor | unknown |
| Product | nested pages |
| Published | Aug 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown nested pages
Be the first to know when new unknown vulnerabilities affecting unknown nested pages are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Nested Pages
0 < 3.2.15
References
Credits
Meher Sudhakar Abbireddi WPScan