plugin

Breakdance Vulnerabilities

13 known security issues reported for the Breakdance WordPress plugin. Most recent disclosed Jul 28, 2026.

3 high 4 medium

Running Breakdance on your site? Check whether your installed version is affected.

Scan your site free

Breakdance <= 2.6.1 - Missing Authorization

medium

The Breakdance plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.6.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.6.1
Fixed in:
2.6.2
Disclosed:
Jul 28, 2026

CVE-2026-65551 on NVD →

Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting via Webhook Action Details

high

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute...

CVSS:
7.2
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Jul 15, 2026

CVE-2026-7543 on NVD →

Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting

high

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...

CVSS:
7.2
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Jul 10, 2026

CVE-2026-57735 on NVD →

Breakdance [breakdance] < 2.0.0

unknown

[en] The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.7.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to export form submissions.

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Aug 1, 2024

CVE-2024-5331 on NVD →

Breakdance [breakdance] < 2.0.0

unknown

[en] The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acces...

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Aug 1, 2024

CVE-2024-5330 on NVD →

Breakdance <= 1.7.2 - Missing Authorization

medium

The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.7.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to export form submissions.

CVSS:
4.3
Affected:
up to 1.7.1
Fixed in:
2.0.0
Disclosed:
Jul 31, 2024

CVE-2024-5331 on NVD →

Breakdance <= 1.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and...

CVSS:
6.4
Affected:
up to 1.7.2
Fixed in:
2.0.0
Disclosed:
Jul 31, 2024

CVE-2024-5330 on NVD →

Breakdance [breakdance] < 1.7.2

unknown

[en] The Breakdance plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.7.1 via post meta data. This is due to the plugin storing custom data in metadata without an underscore prefix. This makes it possible for lower privileged users, such as contributors, to edit this da...

Affected:
up to 1.7.2
Fixed in:
1.7.2
Disclosed:
May 9, 2024

CVE-2024-4605 on NVD →

Breakdance <= 1.7.1 - Authenticated (Contributor+) Remote Code Execution

high

The Breakdance plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.7.1 via post meta data. This is due to the plugin storing custom data in metadata without an underscore prefix. This makes it possible for lower privileged users, such as contributors, to edit this data vi...

CVSS:
8.8
Affected:
up to 1.7.1
Fixed in:
1.7.2
Disclosed:
May 8, 2024

CVE-2024-4605 on NVD →

Breakdance [breakdance] < 1.7.1

unknown

[en] The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom postmeta output in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping on user supplied post meta fields. This makes it possible for authenticated attackers with...

Affected:
up to 1.7.1
Fixed in:
1.7.1
Disclosed:
May 6, 2024

CVE-2023-6854 on NVD →

Breakdance <= 1.7.0 - Authenticated(Contributor+) Stored Cross-Site Scripting via custom postmeta

medium

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom postmeta output in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping on user supplied post meta fields. This makes it possible for authenticated attackers with contr...

CVSS:
6.4
Affected:
up to 1.7.0
Fixed in:
1.7.1
Disclosed:
May 3, 2024

CVE-2023-6854 on NVD →

Breakdance [breakdance] < 1.7.1

unknown

<p>WordPress Breakdance Plugin <= 1.7.0 is vulnerable to Cross Site Scripting (XSS)</p><p>Affected Version <= 1.7.0</p><p>Fixed in version 1.7.1 </p>

Affected:
up to 1.7.1
Fixed in:
1.7.1
Disclosed:
Apr 30, 2024

Breakdance [breakdance] <= 1.7.2 (unfixed)

unknown

[en] : Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.

Affected:
up to 1.7.2
Fix:
No patched version reported
Disclosed:
Apr 3, 2024

CVE-2024-31390 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database