What is CVE-2026-15233?
CVE-2026-15233: The Nested Pages WordPress plugin before version 3.2.15 fails to properly escape post titles in HTML attributes on an admin listing screen. This allows users with the Editor role (or Contributor/Author when the plugin is enabled for the post type) to perform Stored XSS attacks. Updating the plugin to version 3.2.15 or later is strongly recommended.
Azərbaycanca: CVE-2026-15233: Nested Pages WordPress plagininin 3.2.15-dən əvvəlki versiyalarında admin ekranında post başlıqlarının HTML atributlarında düzgün escap edilməməsi zəifliyi aşkarlanıb. Bu, Editor (və müəyyən konfiqurasiyada Contributor/Author) roluna malik istifadəçilərə Stored XSS hücumu təşkil etməyə imkan verir. Plagini dərhal 3.2.15 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
Which user roles can exploit CVE-2026-15233?
Users with the Editor role can exploit this vulnerability. Additionally, when the plugin is enabled for the post type, Contributor and Author roles can also perform Stored XSS attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.