AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-15233

UNKNOWN · CVSS N/A EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

The Nested Pages WordPress plugin prior to version 3.2.15 is vulnerable due to improper escaping of post titles in HTML attributes, enabling users with Editor, Contributor, or Author roles to inject malicious JavaScript. This can lead to cross-site scripting (XSS) attacks, affecting any higher-privileged users who view the administrative listing screen. WordPress site administrators and security teams should prioritize this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-15233
Severity
UNKNOWN
CVSS
N/A
EPSS
0.15%
WordPress Java

Original NVD Description

The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing users with the Editor role (or Contributor/Author when the Nested Pages WordPress plugin before 3.2.15 is enabled for the post type) to inject arbitrary JavaScript that executes in the session of any higher-privileged user who views that screen.