CVE-2026-15233 PUBLISHED

Nested Pages < 3.2.15 - Editor+ Stored XSS via Post Title

Assigner: WPScan
Reserved: 09.07.2026 Published: 04.08.2026 Updated: 04.08.2026

The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing users with the Editor role (or Contributor/Author when the Nested Pages WordPress plugin before 3.2.15 is enabled for the post type) to inject arbitrary JavaScript that executes in the session of any higher-privileged user who views that screen.

Product Status

Vendor Unknown
Product Nested Pages
Versions Default: unaffected
  • affected from 0 to 3.2.15 (excl.)

Credits

  • Meher Sudhakar Abbireddi finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE