๐Ÿ” CVE Alert

CVE-2025-13842

MEDIUM 5.3

Breadcrumb NavXT <= 7.5.0 - Missing Authorization to Sensitive Information Exposure

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions up to and including 7.5.0. This is due to the Gutenberg block renderer trusting the $_REQUEST['post_id'] parameter without verification in the includes/blocks/build/breadcrumb-trail/render.php file. This makes it possible for unauthenticated attackers to enumerate and view breadcrumb trails for draft or private posts by manipulating the post_id parameter, revealing post titles and hierarchy that should remain hidden.

CWE CWE-639
Vendor mtekk
Product breadcrumb navxt
Published Feb 19, 2026
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for mtekk breadcrumb navxt

Be the first to know when new medium vulnerabilities affecting mtekk breadcrumb navxt are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

mtekk / Breadcrumb NavXT
0 โ‰ค 7.5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/62e25985-ac19-41a5-8027-eb053f4a6490?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/breadcrumb-navxt/trunk/includes/blocks/build/breadcrumb-trail/render.php#L17 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3425008

Credits

NosleeP