plugin

Wp Nested Pages Vulnerabilities

22 known security issues reported for the Wp Nested Pages WordPress plugin. Most recent disclosed Jul 27, 2026.

2 high 8 medium 1 low

Running Wp Nested Pages on your site? Check whether your installed version is affected.

Scan your site free

Nested Pages <= 3.2.14 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Nested Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
4.4
Affected:
up to 3.2.14
Fixed in:
3.2.15
Disclosed:
Jul 27, 2026

CVE-2026-15233 on NVD →

Nested Pages <= 3.2.12 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Nested Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arb...

CVSS:
4.4
Affected:
up to 3.2.12
Fixed in:
3.2.13
Disclosed:
Mar 2, 2025

CVE-2025-0718 on NVD →

Nested Pages <= 3.2.9 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Nested Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages t...

CVSS:
4.4
Affected:
up to 3.2.9
Fixed in:
3.2.10
Disclosed:
Jan 24, 2025

CVE-2025-24579 on NVD →

Nested Pages [wp-nested-pages] < 3.2.10

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages allows Stored XSS. This issue affects Nested Pages: from n/a through 3.2.9.

Affected:
up to 3.2.10
Fixed in:
3.2.10
Disclosed:
Jan 24, 2025

CVE-2025-24579 on NVD →

Nested Pages <= 3.2.8 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Nested Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scr...

CVSS:
4.4
Affected:
up to 3.2.8
Fixed in:
3.2.9
Disclosed:
Oct 9, 2024

CVE-2024-8759 on NVD →

Nested Pages [wp-nested-pages] < 3.2.8

unknown

[en] The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.7. This is due to missing or incorrect nonce validation on the 'settingsPage' function and missing santization of the 'tab' parameter. This makes it possible for unauthenticated attackers to...

Affected:
up to 3.2.8
Fixed in:
3.2.8
Disclosed:
Jul 4, 2024

CVE-2024-5943 on NVD →

Nested Pages <= 3.2.7 - Cross-Site Request Forgery to Local File Inclusion

high

The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.7. This is due to missing or incorrect nonce validation on the 'settingsPage' function and missing santization of the 'tab' parameter. This makes it possible for unauthenticated attackers to call...

CVSS:
8.8
Affected:
up to 3.2.7
Fixed in:
3.2.8
Disclosed:
Jul 3, 2024

CVE-2024-5943 on NVD →

Nested Pages [wp-nested-pages] < 3.2.7

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages allows Stored XSS.This issue affects Nested Pages: from n/a through 3.2.6.

Affected:
up to 3.2.7
Fixed in:
3.2.7
Disclosed:
Dec 14, 2023

CVE-2023-49195 on NVD →

Nested Pages <= 3.2.6 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Nested Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbi...

CVSS:
4.4
Affected:
up to 3.2.6
Fixed in:
3.2.7
Disclosed:
Dec 1, 2023

CVE-2023-49195 on NVD →

Nested Pages [wp-nested-pages] < 3.2.4

unknown

[en] The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for authenticated attackers, with editor-level permissions and above, to reset plugin settings.

Affected:
up to 3.2.4
Fixed in:
3.2.4
Disclosed:
May 31, 2023

CVE-2023-2434 on NVD →

Nested Pages <= 3.2.3 - Missing Authorization to Authenticated (Editor+) Plugin Settings Reset

low

The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for authenticated attackers, with editor-level permissions and above, to reset plugin settings.

CVSS:
3.8
Affected:
up to 3.2.3
Fixed in:
3.2.4
Disclosed:
May 30, 2023

CVE-2023-2434 on NVD →

Nested Pages [wp-nested-pages] < 3.1.21

unknown

[en] The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed

Affected:
up to 3.1.21
Fixed in:
3.1.21
Disclosed:
Jun 27, 2022

CVE-2022-1990 on NVD →

Nested Pages <= 3.1.20 - Stored Cross-Site Scripting

medium

The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is disallowed

CVSS:
4.8
Affected:
up to 3.1.21
Fixed in:
3.1.21
Disclosed:
Jun 6, 2022

CVE-2022-1990 on NVD →

Nested Pages [wp-nested-pages] < 3.1.16

unknown

[en] The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions.

Affected:
up to 3.1.16
Fixed in:
3.1.16
Disclosed:
Aug 30, 2021

CVE-2021-38343 on NVD →

Nested Pages [wp-nested-pages] < 3.1.16

unknown

[en] The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status, reassigning their ownership, and editing other metadata.

Affected:
up to 3.1.16
Fixed in:
3.1.16
Disclosed:
Aug 30, 2021

CVE-2021-38342 on NVD →

Nested Pages <= 3.1.15 - Cross-Site Request Forgery to Arbitrary Post Deletion and Modification

high

The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status, reassigning their ownership, and editing other metadata.

CVSS:
8.1
Affected:
up to 3.1.15
Fixed in:
3.1.16
Disclosed:
Aug 25, 2021

CVE-2021-38342 on NVD →

Nested Pages <= 3.1.15 - Open Redirect

medium

The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions.

CVSS:
4.7
Affected:
up to 3.1.15
Fixed in:
3.1.16
Disclosed:
Aug 25, 2021

CVE-2021-38343 on NVD →

Nested Pages <= 3.0.7 - Missing Authorization

medium

The Nested Pages plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 3.0.7. This makes it possible for authenticated attackers to edit other contributors' posts along with modifying the slugs and titles.

CVSS:
6.4
Affected:
up to 3.0.7
Fixed in:
3.0.8
Disclosed:
Mar 26, 2019

Nested Pages [wp-nested-pages] < 3.0.8

unknown

The Nested Pages plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 3.0.7. This makes it possible for authenticated attackers to edit other contributors' posts along with modifying the slugs and titles.

Affected:
up to 3.0.8
Fixed in:
3.0.8
Disclosed:
Mar 26, 2019

Nested Pages [wp-nested-pages] < 3.0.8

unknown

Contributors could quick edit posts not authored by themselves, and could allow them to change the slugs as well as titles.

Affected:
up to 3.0.8
Fixed in:
3.0.8

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database