Description
Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.
Published: 2026-07-02
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Surbma Yoast SEO Breadcrumb Shortcode WordPress plugin versions 1.2 and earlier contains an input validation flaw that fails to escape data supplied through its shortcode, allowing the execution of arbitrary JavaScript when browsers render a page containing the shortcode. This flaw can lead to client‑side script injection that may compromise user data or interfere with site functionality.

Affected Systems

Any WordPress site running the Surbma Yoast SEO Breadcrumb Shortcode plugin at version 1.2 or older is affected. Sites that enable users such as contributors or editors to create or edit content that includes the shortcode present an attack surface for the flaw.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity vulnerability, while the EPSS score of < 1% suggests a very low likelihood of exploitation. The plugin is not listed in CISA’s KEV catalog, implying no widespread exploitation has been reported. The primary attack vector is remote, and it requires the ability to inject or edit content with the shortcode – a privilege level that is inferred from the plugin’s functionality but not explicitly specified in the CVE description.

Generated by OpenCVE AI on July 21, 2026 at 11:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Surbma Yoast SEO Breadcrumb Shortcode to any version newer than 1.2, which removes the unescaped input flaw identified as CWE‑79.
  • If the plugin is not essential for site functionality, uninstall or disable it to eliminate the vulnerable code path.
  • Implement a content security policy that disallows inline scripts wherever possible, reducing the impact of any residual XSS vectors stemming from the plugin or other components.

Generated by OpenCVE AI on July 21, 2026 at 11:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Surbma
Surbma surbma | Yoast Seo Breadcrumb Shortcode
Wordpress
Wordpress wordpress
Vendors & Products Surbma
Surbma surbma | Yoast Seo Breadcrumb Shortcode
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.
Title WordPress Surbma | Yoast SEO Breadcrumb Shortcode plugin <= 1.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Surbma Surbma | Yoast Seo Breadcrumb Shortcode
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T13:58:17.905Z

Reserved: 2026-06-25T08:04:41.580Z

Link: CVE-2026-57764

cve-icon Vulnrichment

Updated: 2026-07-02T13:58:14.592Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')