CVE-2026-84765
massUnauthenticated XSS in Breadcrumb NavXT WordPress plugin (CVE-2026-84765)
An unauthenticated cross-site scripting flaw (CWE-79) affects the Breadcrumb NavXT breadcrumb-navigation plugin for WordPress in all versions up to and including 7.5.1, rated 7.1 (High) with a network attack vector, low attack complexity, no privileges required, and user interaction required. A remote attacker with no account on the site can supply crafted input that the plugin renders into breadcrumb trails, causing malicious JavaScript to execute in the browser of a visitor or administrator who views the affected page. Successful exploitation could let the attacker steal session cookies, redirect users, or perform actions in the victim's session, with the CVSS scope-changed vector indicating the script runs in a different context than where the input is supplied. Any WordPress site running Breadcrumb NavXT 7.5.1 or earlier is affected, which plausibly spans hundreds of thousands of sites. Exploitation has not been confirmed: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.1% probability of exploitation within the next 30 days.
What to do: Update Breadcrumb NavXT to the latest available version above 7.5.1 via the WordPress admin dashboard as soon as possible. If patching must be delayed and breadcrumb navigation is not essential, consider temporarily deactivating the plugin, since no specific workaround is documented. Given the unauthenticated attack vector, administrators of high-traffic sites should prioritize the update even though no in-the-wild exploitation has been reported.
| mtekk Breadcrumb NavXT (WordPress plugin) | <= 7.5.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.