The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 7,288 live websites that are affected by CVE-2026-7543.
| Product | |
| Category | Landing Page Builders |
| Vulnerable Domains | 7,288 live websites (60% of Breakdance install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 29 versions ( 91% of all versions) |
| 2,120 websites | |
| 650 websites | |
| 617 websites | |
| 370 websites | |
| 262 websites | |
| 226 websites | |
| 224 websites | |
| 214 websites | |
| 200 websites | |
| 189 websites |
| .com | 2,659 websites |
| .co.uk | 458 websites |
| .de | 376 websites |
| .nl | 345 websites |
| .org | 251 websites |
| .com.au | 248 websites |
| .se | 183 websites |
| .dk | 177 websites |
| .pl | 171 websites |
| .it | 166 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | **,*** | ||
| ****************.com | **,*** | ||
| ******.com | **,*** | ||
| ****************.com | **,*** | ||
| ************.com | **,*** | ||
| ******.com | ***,*** | ||
| **********.com | ***,*** | ||
| ************.com | ***,*** | ||
| **********.se | ***,*** | ||
| ************.com | ***,*** |
FAQ