Nested Pages <= 3.2.14 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Nested Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 4.4
- Affected:
- up to 3.2.14
- Fixed in:
- 3.2.15
- Disclosed:
- Jul 27, 2026
CVE-2026-15233 on NVD →
Nested Pages <= 3.2.12 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Nested Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arb...
- CVSS:
- 4.4
- Affected:
- up to 3.2.12
- Fixed in:
- 3.2.13
- Disclosed:
- Mar 2, 2025
CVE-2025-0718 on NVD →
Nested Pages <= 3.2.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Nested Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages t...
- CVSS:
- 4.4
- Affected:
- up to 3.2.9
- Fixed in:
- 3.2.10
- Disclosed:
- Jan 24, 2025
CVE-2025-24579 on NVD →
Nested Pages [wp-nested-pages] < 3.2.10
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages allows Stored XSS. This issue affects Nested Pages: from n/a through 3.2.9.
- Affected:
- up to 3.2.10
- Fixed in:
- 3.2.10
- Disclosed:
- Jan 24, 2025
CVE-2025-24579 on NVD →
Nested Pages <= 3.2.8 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Nested Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scr...
- CVSS:
- 4.4
- Affected:
- up to 3.2.8
- Fixed in:
- 3.2.9
- Disclosed:
- Oct 9, 2024
CVE-2024-8759 on NVD →
Nested Pages [wp-nested-pages] < 3.2.8
unknown
[en] The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.7. This is due to missing or incorrect nonce validation on the 'settingsPage' function and missing santization of the 'tab' parameter. This makes it possible for unauthenticated attackers to...
- Affected:
- up to 3.2.8
- Fixed in:
- 3.2.8
- Disclosed:
- Jul 4, 2024
CVE-2024-5943 on NVD →
Nested Pages <= 3.2.7 - Cross-Site Request Forgery to Local File Inclusion
high
The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.7. This is due to missing or incorrect nonce validation on the 'settingsPage' function and missing santization of the 'tab' parameter. This makes it possible for unauthenticated attackers to call...
- CVSS:
- 8.8
- Affected:
- up to 3.2.7
- Fixed in:
- 3.2.8
- Disclosed:
- Jul 3, 2024
CVE-2024-5943 on NVD →
Nested Pages [wp-nested-pages] < 3.2.7
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages allows Stored XSS.This issue affects Nested Pages: from n/a through 3.2.6.
- Affected:
- up to 3.2.7
- Fixed in:
- 3.2.7
- Disclosed:
- Dec 14, 2023
CVE-2023-49195 on NVD →
Nested Pages <= 3.2.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Nested Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbi...
- CVSS:
- 4.4
- Affected:
- up to 3.2.6
- Fixed in:
- 3.2.7
- Disclosed:
- Dec 1, 2023
CVE-2023-49195 on NVD →
Nested Pages [wp-nested-pages] < 3.2.4
unknown
[en] The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for authenticated attackers, with editor-level permissions and above, to reset plugin settings.
- Affected:
- up to 3.2.4
- Fixed in:
- 3.2.4
- Disclosed:
- May 31, 2023
CVE-2023-2434 on NVD →
Nested Pages <= 3.2.3 - Missing Authorization to Authenticated (Editor+) Plugin Settings Reset
low
The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for authenticated attackers, with editor-level permissions and above, to reset plugin settings.
- CVSS:
- 3.8
- Affected:
- up to 3.2.3
- Fixed in:
- 3.2.4
- Disclosed:
- May 30, 2023
CVE-2023-2434 on NVD →
Nested Pages [wp-nested-pages] < 3.1.21
unknown
[en] The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed
- Affected:
- up to 3.1.21
- Fixed in:
- 3.1.21
- Disclosed:
- Jun 27, 2022
CVE-2022-1990 on NVD →
Nested Pages <= 3.1.20 - Stored Cross-Site Scripting
medium
The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed
- CVSS:
- 4.8
- Affected:
- up to 3.1.21
- Fixed in:
- 3.1.21
- Disclosed:
- Jun 6, 2022
CVE-2022-1990 on NVD →
Nested Pages [wp-nested-pages] < 3.1.16
unknown
[en] The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions.
- Affected:
- up to 3.1.16
- Fixed in:
- 3.1.16
- Disclosed:
- Aug 30, 2021
CVE-2021-38343 on NVD →
Nested Pages [wp-nested-pages] < 3.1.16
unknown
[en] The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status, reassigning their ownership, and editing other metadata.
- Affected:
- up to 3.1.16
- Fixed in:
- 3.1.16
- Disclosed:
- Aug 30, 2021
CVE-2021-38342 on NVD →
Nested Pages <= 3.1.15 - Cross-Site Request Forgery to Arbitrary Post Deletion and Modification
high
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status, reassigning their ownership, and editing other metadata.
- CVSS:
- 8.1
- Affected:
- up to 3.1.15
- Fixed in:
- 3.1.16
- Disclosed:
- Aug 25, 2021
CVE-2021-38342 on NVD →
Nested Pages <= 3.1.15 - Open Redirect
medium
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions.
- CVSS:
- 4.7
- Affected:
- up to 3.1.15
- Fixed in:
- 3.1.16
- Disclosed:
- Aug 25, 2021
CVE-2021-38343 on NVD →
Nested Pages <= 3.0.7 - Missing Authorization
medium
The Nested Pages plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 3.0.7. This makes it possible for authenticated attackers to edit other contributors' posts along with modifying the slugs and titles.
- CVSS:
- 6.4
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.8
- Disclosed:
- Mar 26, 2019
Nested Pages [wp-nested-pages] < 3.0.8
unknown
The Nested Pages plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 3.0.7. This makes it possible for authenticated attackers to edit other contributors' posts along with modifying the slugs and titles.
- Affected:
- up to 3.0.8
- Fixed in:
- 3.0.8
- Disclosed:
- Mar 26, 2019
Nested Pages [wp-nested-pages] < 3.0.8
unknown
Contributors could quick edit posts not authored by themselves, and could allow them to change the slugs as well as titles.
- Affected:
- up to 3.0.8
- Fixed in:
- 3.0.8
Nested Pages [wp-nested-pages] < 3.2.13
unknown
- Affected:
- up to 3.2.13
- Fixed in:
- 3.2.13
CVE-2025-0718 on NVD →
Nested Pages [wp-nested-pages] < 3.2.9
unknown
- Affected:
- up to 3.2.9
- Fixed in:
- 3.2.9
CVE-2024-8759 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database