Executive brief
The Genzel breadcrumbs plugin for WordPress, which helps website visitors navigate through a site's hierarchy, contains a security flaw that allows unauthorized changes to its settings. By tricking a site administrator into clicking a malicious link, an attacker can remotely modify the website's breadcrumb configuration, including navigation labels and links. This could lead to unauthorized changes in how the site is displayed or redirect users to incorrect locations.
Technical details
The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the _options_page function. This vulnerability affects all versions up to and including 1.2. An unauthenticated attacker can exploit this by crafting a malicious request and tricking a logged-in site administrator into executing it (e.g., via a phishing link). Successful exploitation allows the attacker to update the plugin's configuration, including templates, delimiters, home labels, home URIs, and breadcrumb rules. The vulnerability is classified as CWE-352.
Affected products
- Genzel Genzel breadcrumbs Up to, and including, 1.2
Timeline
- 2026-05-27: disclosed: Initial publication of the CVE record.
- 2026-05-27: advisory: Wordfence published the vulnerability details.
References
- https://plugins.trac.wordpress.org/browser/genzel-breadcrumbs/trunk/gb.class.php
- https://plugins.trac.wordpress.org/browser/genzel-breadcrumbs/trunk/gb.class.php
- https://plugins.trac.wordpress.org/browser/genzel-breadcrumbs/trunk/page-options.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/e9e4ffa9-9f61-42e8-85f5-1dea499a63f7?source=cve