First published: Sun Mar 23 2025(Updated: )
The Nested Pages WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nested Pages | <3.2.13 | |
Kyle Phillips Nested Pages | <3.2.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0718 is considered a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
To fix CVE-2025-0718, update the Nested Pages WordPress plugin to version 3.2.13 or higher.
CVE-2025-0718 affects users of the Nested Pages WordPress plugin versions before 3.2.13.
CVE-2025-0718 allows high privilege users to execute Stored Cross-Site Scripting attacks.
The implications of CVE-2025-0718 include the risk of unauthorized script execution in the context of a user's session.