CVE-2025-13842
The Breadcrumb NavXT plugin versions 7.5.0 and earlier are susceptible to an authorization bypass vulnerability when user-controlled input is used in the post_id parameter within the Gutenberg block renderer. This flaw allows unauthenticated attackers to exploit the $_REQUEST['post_id'] without proper validation, enabling them to access breadcrumb trails for draft or private posts, thereby exposing sensitive information such as post titles and hierarchical structure that should remain concealed.
Based on public CVE data (MITRE/NVD).