Authorization Bypass in Breadcrumb NavXT Plugin for WordPress
CVE-2025-13842
5.3MEDIUM
What is CVE-2025-13842?
The Breadcrumb NavXT plugin for WordPress is susceptible to an authorization bypass vulnerability, enabling unauthenticated users to manipulate the 'post_id' parameter in the $_REQUEST array. This flaw, found in the Gutenberg block renderer, allows attackers to enumerate and access breadcrumb trails associated with private or draft posts. As a result, information like post titles and their hierarchy, which are intended to remain confidential, may be disclosed improperly.
Affected Version(s)
Breadcrumb NavXT 0 <= 7.5.0