Strategic Overview
- Status
- Patched in 3.1.16
- Affected Plugin
- Nested Pages
- Affected Version
<= 3.1.15- CVSS
- 4.7Medium
- Weakness type
- CWE-601 · URL Redirection to Untrusted Site ('Open Redirect')
- CVE
CVE-2021-38343
At a glance
CVE-2021-38343 is a medium-severity URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the Nested Pages WordPress plugin, affecting versions <= 3.1.15. It carries a CVSS score of 4.7 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 3.1.16; sites on affected versions should update now. Disclosed August 2021, reported by Ram.
Vulnerability Overview
The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site.
CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
Reaching this weakness in Nested Pages <= 3.1.15 takes a caller who can reach the endpoint. An open redirect is a page that takes a destination from the request and sends the browser there without checking that the destination belongs to the site.
A link that starts on a trusted domain finishes on an attacker's, which is what makes phishing and consent-screen abuse credible to the person clicking it. For Nested Pages the fix is 3.1.16: builds <= 3.1.15 are affected, anything from 3.1.16 onward is not.
Remediation
Update to version 3.1.16, or a newer patched version
How does WordSec protect against this?
The attempt arrives as an ordinary request to Nested Pages: WordSec's web application firewall inspects request payloads before WordPress loads them. None of that substitutes for the fix: Nested Pages 3.1.16 closes this, and updating the plugin is the step that ends it.
- Firewall
- Alerts
External References
Related records
Other vulnerabilities in Nested Pages
- 8.8CVE-2024-5943: Nested Pages <= 3.2.7 CSRF to Local File Inclusion
CVE-2024-5943 - 8.1CVE-2021-38342: Nested Pages CSRF
CVE-2021-38342 - 6.4Nested Pages <= 3.0.7 Missing Authorization
- 4.8CVE-2022-1990: Nested Pages <= 3.1.20 Stored Cross-Site Scripting
CVE-2022-1990 - 4.4CVE-2026-15233: Nested Pages <= 3.2.14 Stored Cross-Site Scripting
CVE-2026-15233 - 4.4CVE-2025-0718: Nested Pages <= 3.2.12 Stored Cross-Site Scripting
CVE-2025-0718 - 4.4CVE-2025-24579: Nested Pages <= 3.2.9 Stored Cross-Site Scripting
CVE-2025-24579 - 4.4CVE-2024-8759: Nested Pages <= 3.2.8 Stored Cross-Site Scripting
CVE-2024-8759
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C