CVE · Medium

CVE-2025-13842 — Breadcrumb NavXT [breadcrumb-navxt] < 7.5.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13842 Breadcrumb NavXT [breadcrumb-navxt] < 7.5.1 Authorization Bypass Through User-Controlled Key Medium 5.3 < 7.5.1 7.5.1 2026-02-18

CVE-2025-13842

The Breadcrumb NavXT plugin versions 7.5.0 and earlier are susceptible to an authorization bypass vulnerability when user-controlled input is used in the post_id parameter within the Gutenberg block renderer. This flaw allows unauthenticated attackers to exploit the $_REQUEST['post_id'] without proper validation, enabling them to access breadcrumb trails for draft or private posts, thereby exposing sensitive information such as post titles and hierarchical structure that should remain concealed.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.