Breakdance <= 2.6.1 - Missing Authorization
medium
The Breakdance plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.6.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.2
- Disclosed:
- Jul 28, 2026
CVE-2026-65551 on NVD →
Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting via Webhook Action Details
high
The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute...
- CVSS:
- 7.2
- Affected:
- up to 2.7.1
- Fixed in:
- 2.7.2
- Disclosed:
- Jul 15, 2026
CVE-2026-7543 on NVD →
Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting
high
The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...
- CVSS:
- 7.2
- Affected:
- up to 2.7.1
- Fixed in:
- 2.7.2
- Disclosed:
- Jul 10, 2026
CVE-2026-57735 on NVD →
Breakdance [breakdance] < 2.0.0
unknown
[en] The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.7.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to export form submissions.
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
- Disclosed:
- Aug 1, 2024
CVE-2024-5331 on NVD →
Breakdance [breakdance] < 2.0.0
unknown
[en] The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acces...
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
- Disclosed:
- Aug 1, 2024
CVE-2024-5330 on NVD →
Breakdance <= 1.7.2 - Missing Authorization
medium
The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.7.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to export form submissions.
- CVSS:
- 4.3
- Affected:
- up to 1.7.1
- Fixed in:
- 2.0.0
- Disclosed:
- Jul 31, 2024
CVE-2024-5331 on NVD →
Breakdance <= 1.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and...
- CVSS:
- 6.4
- Affected:
- up to 1.7.2
- Fixed in:
- 2.0.0
- Disclosed:
- Jul 31, 2024
CVE-2024-5330 on NVD →
Breakdance [breakdance] < 1.7.2
unknown
[en] The Breakdance plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.7.1 via post meta data. This is due to the plugin storing custom data in metadata without an underscore prefix. This makes it possible for lower privileged users, such as contributors, to edit this da...
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- May 9, 2024
CVE-2024-4605 on NVD →
Breakdance <= 1.7.1 - Authenticated (Contributor+) Remote Code Execution
high
The Breakdance plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.7.1 via post meta data. This is due to the plugin storing custom data in metadata without an underscore prefix. This makes it possible for lower privileged users, such as contributors, to edit this data vi...
- CVSS:
- 8.8
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.2
- Disclosed:
- May 8, 2024
CVE-2024-4605 on NVD →
Breakdance [breakdance] < 1.7.1
unknown
[en] The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom postmeta output in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping on user supplied post meta fields. This makes it possible for authenticated attackers with...
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- May 6, 2024
CVE-2023-6854 on NVD →
Breakdance <= 1.7.0 - Authenticated(Contributor+) Stored Cross-Site Scripting via custom postmeta
medium
The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom postmeta output in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping on user supplied post meta fields. This makes it possible for authenticated attackers with contr...
- CVSS:
- 6.4
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.1
- Disclosed:
- May 3, 2024
CVE-2023-6854 on NVD →
Breakdance [breakdance] < 1.7.1
unknown
<p>WordPress Breakdance Plugin <= 1.7.0 is vulnerable to Cross Site Scripting (XSS)</p><p>Affected Version <= 1.7.0</p><p>Fixed in version 1.7.1 </p>
- Affected:
- up to 1.7.1
- Fixed in:
- 1.7.1
- Disclosed:
- Apr 30, 2024
Breakdance [breakdance] <= 1.7.2 (unfixed)
unknown
[en] : Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.
- Affected:
- up to 1.7.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 3, 2024
CVE-2024-31390 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database