VYPR
High severity7.1NVD Advisory· Published Jul 4, 2025· Updated Apr 23, 2026

CVE-2025-28978

CVE-2025-28978

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hung Trang Si SB Breadcrumbs sb-breadcrumbs allows Reflected XSS.This issue affects SB Breadcrumbs: from n/a through <= 1.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in WordPress SB Breadcrumbs plugin <=1.0 allows script injection via crafted links, with high likelihood of mass exploitation.

Vulnerability

Description The SB Breadcrumbs plugin for WordPress versions 1.0 and earlier contains a reflected Cross-site Scripting (XSS) vulnerability caused by improper neutralization of user input during web page generation [1]. This flaw occurs when the plugin fails to sanitize or escape user-supplied data before including it in output, allowing an attacker to inject arbitrary HTML or JavaScript [1].

Exploitation

Method Exploitation requires user interaction, such as clicking a maliciously crafted link or visiting a specially crafted page [1]. An unauthenticated attacker can craft a URL containing a malicious script payload; once a victim clicks the link, the payload executes in the context of the victim's browser session [1]. No elevated privileges are needed to initiate the attack, though a privileged user must be tricked into performing the action [1].

Impact

Successful exploitation enables an attacker to inject malicious scripts that can perform actions like redirecting visitors to attacker-controlled sites, displaying advertisements, or stealing session cookies [1]. This can lead to defacement, phishing, or further compromise of the WordPress site and its users [1].

Mitigation

Status The vendor has not released an official patch, but Patchstack has provided a virtual mitigation rule to block attacks until an update becomes available [1]. Immediate plug-in update is recommended; if not possible, users should contact their hosting provider for assistance [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.