Impact
The vulnerability is a client‑side injection flaw that allows an attacker to insert arbitrary JavaScript into pages that use the Breadcrumb NavXT plugin. It is described as unauthenticated, meaning no user privilege is required to exploit it. If successful, the attacker can execute scripts within the context of any visitor, potentially enabling cookie theft, session hijacking, or site defacement. This type of flaw falls under CWE‑79.
Affected Systems
WordPress sites that are running the Breadcrumb NavXT plugin versions 7.5.1 or earlier. The product is maintained by John Havlik and is commonly used to display breadcrumb navigation on WordPress sites.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity. Because the vulnerability is unauthenticated and can be triggered from any web request, the likelihood of exploitation is non‑negligible, although EPSS data is not available. The vulnerability is not listed in CISA’s KEV catalog, but tools that process CVSS can still surface it as a high‑risk issue. An attacker can typically trigger the flaw by crafting a malicious URL or input that reaches a page rendering the breadcrumb trail, causing the browser to execute injected JavaScript.
OpenCVE Enrichment