CVE-2026-84765: WordPress Breadcrumb NavXT plugin <= 7.5.1 - Cross Site Scripting (XSS) vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions.
Affected Software
1 affected component
WordPress Breadcrumb NavXT plugin<=7.5.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Breadcrumb NavXTto a version that resolves this vulnerability.Fixed in 7.5.2
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or plugin privileges. Exploitation still requires user interaction, as indicated by the UI:R vector.
2
Which installations are affected?
WordPress sites using Breadcrumb NavXT version 7.5.1 or earlier are affected according to the available data.
3
What is the potential impact?
Successful exploitation can affect confidentiality, integrity, and availability at low impact levels. The CVSS vector also indicates the impact can extend beyond the vulnerable component's security scope.