Description
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
Published: 2026-09-30
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a PHP Object Injection flaw in the WordPress Nested Pages plugin that allows attackers to manipulate serialized data, leading to arbitrary code execution and full compromise of the affected WordPress site, including confidentiality, integrity, and availability.

Affected Systems

The affected products are the WordPress Nested Pages plugin by Hook & Filter for WordPress installations running version 3.3.2 or older; the plugin can be installed on any public WordPress site.

Risk and Exploitability

The CVSS score of 9.8 reflects a critical severity, but the EPSS score is not available and the flaw is not listed in CISA KEV, indicating no publicly known active exploits at the time of analysis. The likely attack vector is remote, via crafted HTTP requests that trigger the unsanitized deserialization within the plugin; authentication is not required to exploit this vulnerability.

Generated by OpenCVE AI on September 30, 2026 at 18:46 UTC.

Remediation

Vendor Solution

Update the WordPress Nested Pages plugin to the latest available version (at least 3.3.3).


OpenCVE Recommended Actions

  • Update the WordPress Nested Pages plugin to version 3.3.3 or newer.
  • If an immediate update is not feasible, temporarily disable or uninstall the Nested Pages plugin to block exploitation until a patch is applied.
  • Ensure that all other WordPress plugins and the core are up to date, and verify that no outdated copies of the plugin remain on the server.

Generated by OpenCVE AI on September 30, 2026 at 18:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Hook & Filter
Hook & Filter nested Pages
Wordpress-extensions
Wordpress-extensions nested Pages
Vendors & Products Hook & Filter
Hook & Filter nested Pages
Wordpress-extensions
Wordpress-extensions nested Pages

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
Title WordPress Nested Pages plugin <= 3.3.2 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Hook & Filter Nested Pages
Wordpress-extensions Nested Pages
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T17:59:55.366Z

Reserved: 2026-09-26T00:17:50.215Z

Link: CVE-2026-100512

cve-icon Vulnrichment

Updated: 2026-09-30T17:59:19.370Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T18:17:59.300

Modified: 2026-09-30T19:04:41.917

Link: CVE-2026-100512

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T19:35:46Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data