Kylephillips maintains a narrowly scoped product portfolio centered on the Nested Pages plugin, a web-based page management component with a durable weakness pattern rooted in web-application input handling and access control. The recurring vulnerability classes—cross-site scripting, cross-site request forgery, missing authorization checks, and open redirects—reflect common attack surfaces in form-driven and navigation-oriented web plugins where user input flows directly into rendered output or state-changing operations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kylephillips over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5943HIGH The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.7. This is due to missing or incorrect nonce validation | Jul 4, 2024 | 8.8 | 26 | NO | NO |
CVE-2021-38342HIGH The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to t | Aug 30, 2021 | 8.1 | 24 | NO | NO |
CVE-2021-38343MEDIUM The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryF | Aug 30, 2021 | 6.1 | 20 | NO | NO |
CVE-2025-24579MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages wp-nested-pages allows Stored XSS.This issue affect | Jan 24, 2025 | 5.9 | 17 | NO | NO |
CVE-2025-0718MEDIUM The Nested Pages WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cro | Mar 23, 2025 | 4.8 | 16 | NO | NO |
CVE-2022-1990MEDIUM The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow high privilege users to perform Stored Cross-Site Scripting | Jun 27, 2022 | 4.8 | 16 | NO | NO |
CVE-2024-8759MEDIUM The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site | May 15, 2025 | 4.8 | 14 | NO | NO |
CVE-2023-49195MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages allows Stored XSS.This issue affects Nested Pages: | Dec 14, 2023 | 4.8 | 14 | NO | NO |
The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. | May 31, 2023 | 3.8 | 13 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kylephillips.
Media articles that mention a CVE ID that affects a product developed by Kylephillips — matched by CVE ID, not by vendor name.