Kylephillips
Kylephillips Nested Pages: vulnerabilidades y CVE
Kylephillips Nested Pages tiene 11 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses2
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-100512 | Crítica (9.8) | 0.56% | — | 30 sept 2026 | Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions. |
| CVE-2026-15233 | Media (4.8) | 0.24% | — | 4 ago 2026 | The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing users with the Editor role (or… |
| CVE-2024-8759 | Media (4.8) | 0.34% | — | 15 may 2025 | The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2025-0718 | Media (4.8) | 0.26% | — | 23 mar 2025 | The Nested Pages WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2025-24579 | Media (5.9) | 0.38% | — | 24 ene 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages wp-nested-pages allows Stored XSS.This issue affects Nested Pages: from n/a through <=… |
| CVE-2024-5943 | Alta (8.8) | 0.29% | — | 4 jul 2024 | The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.7. This is due to missing or incorrect nonce validation on the 'settingsPage' function and… |
| CVE-2023-49195 | Media (4.8) | 0.39% | — | 14 dic 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages allows Stored XSS.This issue affects Nested Pages: from n/a through 3.2.6. |
| CVE-2023-2434 | Baja (3.8) | 0.66% | — | 31 may 2023 | The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for… |
| CVE-2022-1990 | Media (4.8) | 0.67% | — | 27 jun 2022 | The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltered_html is… |
| CVE-2021-38343 | Media (6.1) | 0.83% | — | 30 ago 2021 | The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions. |
| CVE-2021-38342 | Alta (8.1) | 0.49% | — | 30 ago 2021 | The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary… |