External risk intelligence

Nested Pages Plugin PHP Object Injection

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-100512

This vulnerability affects a WordPress plugin. WordPress plugins are commonly deployed as part of public-facing web applications, making the code paths within them frequently reachable over the public internet in standard web server configurations.

Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security issue has been identified in the Nested Pages plugin for WordPress. This vulnerability could allow an unauthorized party to inject malicious code into systems using this plugin, potentially impacting the confidentiality, integrity, and availability of data. The main concern is to confirm if this plugin is in use and assess any associated exposure.

  • Code injection flaw in a WordPress plugin.
  • Affects a commonly used website component.
  • Verify usage to understand potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a crafted request over the network to a vulnerable website that uses the affected plugin. This could allow them to inject malicious PHP objects, potentially leading to unauthorized actions or data compromise on the server.

  • No authentication required.
  • Unserialized user input.
  • Server-side code execution.

Live Threat

Current exploitation, exposure, and threat context

A PHP Object Injection vulnerability in the Nested Pages plugin could allow an unauthenticated attacker to execute arbitrary code on the affected server when a specially crafted request is made. This could lead to a complete compromise of the website and its underlying server.

  • Plugin code and server-side logic.
  • Via specially crafted network requests.
  • Arbitrary code execution and server compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

Determining the exact ownership for this PHP Object Injection vulnerability requires understanding your specific deployment. Typically, application owners or platform teams responsible for managing WordPress instances and their plugins will lead the remediation efforts. The first practical step is to identify all instances of the affected plugin, confirm their exposure and criticality, and then engage the accountable teams to plan a risk-based response.

  • Plugin owners should manage this issue.
  • Verify plugin reachability and business impact.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Nested Pages plugin for WordPress?

Nested Pages is a WordPress plugin designed to simplify content management by providing an intuitive drag-and-drop interface for organizing pages and posts. It essentially upgrades the standard WordPress dashboard, allowing site administrators to manage complex site hierarchies more efficiently than the default menu tools.

What does PHP Object Injection mean for CVE-2026-100512?

This vulnerability falls under the CWE-502 weakness class, which happens when an application deserializes untrusted data without proper validation. In this CVE, the plugin improperly handles user-provided data, allowing an attacker to inject malicious objects. This can trick the application into executing unintended code, potentially leading to a full server compromise.

How does an attacker trigger this vulnerability?

An attacker triggers the flaw by sending a specifically crafted network request to a site running a vulnerable version of the plugin. Because the issue occurs during the handling of input, it does not require the attacker to have an existing user account. However, simply visiting the site or clicking a link will not trigger the bug; the request must be intentionally malformed to exploit the deserialization process.

Why should I care about this vulnerability?

According to Halo Surface Signal, this plugin is frequently used in public-facing web applications. Since the code paths are often reachable over the public internet, websites using this software are at a higher risk of being targeted by remote, unauthenticated attackers, making it a critical item to address.

What steps should I take if I use Nested Pages?

Start by identifying every WordPress instance where the Nested Pages plugin is installed. Once you have an inventory, evaluate whether these sites are exposed to the internet. Work with your platform or web management teams to verify if you are running version 3.3.2 or older, and prioritize updating or disabling the plugin until you can confirm your deployment is secure.

References