CVE-2026-15233
MEDIUMNested Pages < 3.2.15 - Editor+ Stored XSS via Post Title
Title source: cnaDescription
The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing users with the Editor role (or Contributor/Author when the Nested Pages WordPress plugin before 3.2.15 is enabled for the post type) to inject arbitrary JavaScript that executes in the session of any higher-privileged user who views that screen.
References (1)
Core 1
Core References
Exploit exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/c0376718-4bea-4e1e-a76c-100799cb9b25/
Scores
CVSS v3
4.8
EPSS
0.0014
EPSS Percentile
4.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
None/Nested Pages
< 3.2.15
Published
Aug 04, 2026
Tracked Since
Aug 04, 2026