Breadcrumb NavXT <= 7.5.0 - Missing Authorization to Sensitive Information Exposure
medium
The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions up to and including 7.5.0. This is due to the Gutenberg block renderer trusting the $_REQUEST['post_id'] parameter without verification in the includes/blocks/build/breadcrumb-trail/render.php file. T...
- CVSS:
- 5.3
- Affected:
- up to 7.5.0
- Fixed in:
- 7.5.1
- Disclosed:
- Feb 18, 2026
CVE-2025-13842 on NVD →
Breadcrumb NavXT < 7.5.1 - Sensitive Information Exposure
medium
- Affected:
- up to 7.5.1
- Fixed in:
- 7.5.1
- Disclosed:
- Feb 18, 2026
CVE-2025-13842 on NVD →
Breadcrumb NavXT < 6.2.0 - Username Disclosure via REST API
unknown
- Affected:
- up to 6.2.0
- Fixed in:
- 6.2.0
- Disclosed:
- Sep 28, 2018
Breadcrumb NavXT <= 6.1.0 - Sensitive Data Exposure
medium
The Breadcrumb NavXT plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including 6.1.0. This can allow unauthorized attackers to extract sensitive data including sensitive information that may help in launching further attacks, such as username disclosure.
- CVSS:
- 5.3
- Affected:
- up to 6.1.0
- Fixed in:
- 6.2.0
- Disclosed:
- Sep 26, 2018
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database