Conversation
supportApparently, this vulnerability was found with the plugin back in March. Is this something that will be fixed? For now, I’ve deactivated the plugin on all sites that use it. https://research.cleantalk.org/reports/search/wp-nested-pages/CVE-2025-0718
This has been fixed in v3.2.13, see https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-nested-pages/nested-pages-3212-authenticated-contributor-stored-cross-site-scripting
This has been fixed in v3.2.13, see https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-nested-pages/nested-pages-3212-authenticated-contributor-stored-cross-site-scripting