๐Ÿ” CVE Alert

CVE-2026-15233

UNKNOWN 0.0

Nested Pages < 3.2.15 - Editor+ Stored XSS via Post Title

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing users with the Editor role (or Contributor/Author when the Nested Pages WordPress plugin before 3.2.15 is enabled for the post type) to inject arbitrary JavaScript that executes in the session of any higher-privileged user who views that screen.

Vendor unknown
Product nested pages
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for unknown nested pages

Be the first to know when new unknown vulnerabilities affecting unknown nested pages are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Nested Pages
0 < 3.2.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c0376718-4bea-4e1e-a76c-100799cb9b25/

Credits

Meher Sudhakar Abbireddi WPScan