CVE-2026-100512: WordPress Nested Pages plugin <= 3.3.2 - PHP Object Injection vulnerability
Published Sep 30, 2026
·Updated
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
Affected Software
1 affected component
WordPress Nested Pages<=3.3.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Nested Pages pluginto a version that resolves this vulnerability.Fixed in 3.3.3
Event History
Sep 30, 2026
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires a user with the Contributor role in WordPress. The vulnerability does not require user interaction.
2
Which installations are affected?
WordPress sites using the Nested Pages plugin version 3.3.2 or earlier are affected.
3
What is the potential impact?
The issue is rated critical with high impact to confidentiality, integrity, and availability. It is remotely exploitable with low attack complexity.