Vulnerabilities and security researches forbreadcrumb-navxt breadcrumb-navxt
Direction: ascendingJun 07, 2024
Breadcrumb NavXT # b17256c9b28e12c8f98b31f219ba84555fddfe63
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 03, 2018
- Research Description
- Breadcrumb NavXT [breadcrumb-navxt] < 6.2.0 WordPress Breadcrumb NavXT plugin <= 6.1.0 - Username Disclosure via REST API Username Disclosure via REST API issue found by Janek Vind in WordPress Breadcrumb NavXT plugin (versions <= 6.1.0).
- Affected versions
-
max 6.2.0.
- Status
-
vulnerable
Feb 04, 2025
Breadcrumb NavXT # PSC-2024-64552
- PSC, Research URL
- Home page URL
- Application
- Date
- Aug 05, 2025
- Research Description
- Breadcrumb NavXT is a powerful WordPress plugin designed to generate breadcrumb trails for websites, providing users with a clear navigational structure. As the successor to Breadcrumb Navigation XT, it has been completely rebuilt to offer greater customization, performance, and compatibility with modern web standards. The plugin integrates seamlessly with WordPress themes, allowing both administrators and developers to configure breadcrumb settings effortlessly.
- Affected versions
-
Min 7.5.1, max 7.5.1.
- Status
-
SAFE & CERTIFIED
Mar 28, 2026
Breadcrumb NavXT # CVE-2025-13842
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 19, 2026
- Research Description
- The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions up to and including 7.5.0. This is due to the Gutenberg block renderer trusting the $_REQUEST['post_id'] parameter without verification in the includes/blocks/build/breadcrumb-trail/render.php file. This makes it possible for unauthenticated attackers to enumerate and view breadcrumb trails for draft or private posts by manipulating the post_id parameter, revealing post titles and hierarchy that should remain hidden.
- Affected versions
-
max 7.5.1.
- Status
-
vulnerable
Jun 16, 2026
Breadcrumb NavXT # 976b7d90-7695-4353-aae2-09c87154ff22
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Breadcrumb NavXT [breadcrumb-navxt] < 6.2.0 wpscan.com
- Affected versions
-
max 6.2.0.
- Status
-
vulnerable
Breadcrumb NavXT # 0e7f1c317dd6b0395ed6988fd37fb1bdef1339d3
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 26, 2018
- Research Description
- Breadcrumb NavXT [breadcrumb-navxt] < 6.2.0 Breadcrumb NavXT <= 6.1.0 - Sensitive Data Exposure The Breadcrumb NavXT plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including 6.1.0. This can allow unauthorized attackers to extract sensitive data including sensitive information that may help in launching further attacks, such as username disclosure.
- Affected versions
-
max 6.2.0.
- Status
-
vulnerable