Ghostwire

CVE-2026-15233: The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML...

MEDIUM CVSS 0.0

Published: August 4, 2026 | Last Modified: August 4, 2026

Description

The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing users with the Editor role (or Contributor/Author when the Nested Pages WordPress plugin before 3.2.15 is enabled for the post type) to inject arbitrary JavaScript that executes in the session of any higher-privileged user who views that screen.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References