Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 19 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mtekk
Mtekk breadcrumb Navxt Wordpress Wordpress wordpress |
|
| Vendors & Products |
Mtekk
Mtekk breadcrumb Navxt Wordpress Wordpress wordpress |
Thu, 19 Feb 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions up to and including 7.5.0. This is due to the Gutenberg block renderer trusting the $_REQUEST['post_id'] parameter without verification in the includes/blocks/build/breadcrumb-trail/render.php file. This makes it possible for unauthenticated attackers to enumerate and view breadcrumb trails for draft or private posts by manipulating the post_id parameter, revealing post titles and hierarchy that should remain hidden. | |
| Title | Breadcrumb NavXT <= 7.5.0 - Missing Authorization to Sensitive Information Exposure | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:57:10.579Z
Reserved: 2025-12-01T18:55:52.648Z
Link: CVE-2025-13842
Updated: 2026-02-19T17:22:53.708Z
Status : Deferred
Published: 2026-02-19T07:17:33.260
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-13842
No data.
OpenCVE Enrichment
Updated: 2026-04-21T16:00:13Z