Impact
The Nested Pages WordPress plugin prior to version 3.2.15 has a stored cross‑site scripting flaw that fails to escape post titles when they are written into HTML attributes on an administrative listing screen. An Editor, or a Contributor or Author when the plugin is turned on for that post type, can create a post title that contains malicious JavaScript. When a higher‑privileged user later views the listing, the script executes within that user’s browser session, allowing the attacker to hijack the session, steal credentials, or perform other client‑side actions. This flaw therefore provides a clear client‑side code execution path for users with the appropriate roles, and it is caused by improper input validation (CWE‑79).
Affected Systems
WordPress installations that have the Nested Pages plugin installed in any version older than 3.2.15 are vulnerable. The flaw applies regardless of site size or custom configuration and is triggered when the plugin’s post type is enabled for Editors, Contributors, or Authors.
Risk and Exploitability
The EPSS score of less than 1 % indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 4.8 classifies the flaw as moderate severity. Exploitation requires a legitimate user with an Editor, Contributor, or Author role to craft a malicious post title, after which any higher‑privileged user who views the affected administrative screen becomes a victim. While the risk level is moderate, the impact of code execution on privileged users warrants timely remediation.
OpenCVE Enrichment