CVE-2026-7543

Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting via Webhook Action Details

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 7,288 live websites that are affected by CVE-2026-7543.

Run a Free Instant Scan




Affected Software

Product  Breakdance
Category Landing Page Builders
Vulnerable Domains7,288 live websites (60% of Breakdance install base)
Vulnerable Versions
  • from 0 through 2.7.1
Vulnerable Versions Count29 versions ( 91% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 16, 2026
  • Updated - Jul 17, 2026

Credits

  • h0xilo (finder)

Website Distribution by Country

Number of websites using CVE-2026-7543
United States2,120 websites



GB650 websites
Germany617 websites
Netherlands370 websites
Australia262 websites
Poland226 websites
Denmark224 websites
Italy214 websites
Sweden200 websites
France189 websites

Website Distribution by TLD

Number of websites using CVE-2026-7543
.com2,659 websites
.co.uk458 websites
.de376 websites
.nl345 websites
.org251 websites
.com.au248 websites
.se183 websites
.dk177 websites
.pl171 websites
.it166 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-7543

Top websites that are affected by CVE-2026-7543. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States**,***
****************.com United States**,***
******.com United States**,***
****************.com United States**,***
************.com United States**,***
******.com United States***,***
**********.com United States***,***
************.com United States***,***
**********.se Sweden***,***
************.com United States***,***
See full domain list

FAQ

CVE-2026-7543 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Breakdance
A total of 7,288 websites have been identified as vulnerable to CVE-2026-7543, based on global website indexing conducted by WebTechSurvey.
The Breakdance is affected by the CVE-2026-7543 vulnerability.
Breakdance versions up to and including 2.7.1 are vulnerable to CVE-2026-7543.