Better Section Navigation

Better Section Navigation has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Better Section Navigation has a vendor fix available, so running the current release closes it.

All of these findings were reported by Muhammad Yudha - DJ. Better Section Navigation is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Better Section Navigation vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2025-31465

Better Section Navigation Widget <= 1.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Better Section Navigation banner
Latestv1.7.0

Better Section Navigation

cornershop

Author

cornershop

5.0(4)
100/100
Last Updated
2025-12-03 (9mo ago)
Active Installs
600+
Downloads
16,505
Requires WP
2.8+
Requires PHP
5.6+
Tested up to
WP 6.9.7
Created
2017-06-14 (9y ago)

Adds a new widget type you can deploy in your sidebar regions (and/or elsewhere) to display section-based navigation, along with the ability to exclude certain pages from showing up. The title of the widget is the top level page within the current section. The widget then can show all of the page’s published siblings (except on the top level page), all parents and grandparents (and higher), the siblings of all parents and grandparents (up to top level page), and any immediate children of the current page. It can also be called by a function inside template files. It includes a simple widget configuration panel. From this panel you can: Determine whether the widget should appear on the home page Override standard behavior and have the widget show all pages in the current section Determine whether the widget should appear even if the section only has one page (the top level) Provide a list of pages to exclude from the output Determine whether the section navigation should still appear when viewing excluded pages Use a specific widget title (i.e. In This Section), or just use the top level page title Determine whether the section title should be linked Determine page sort order (defaults to menu order) The widget uses standard WordPress navigation classes, in addition to a unique class around the widget, for easy styling. The UL of the page list also has a custom class, bsn-list, that can be altered via the bsn_list_class filter. Beginning with version 1.5, Better Section Navigation also incorporates the features of the defunct Exclude Pages plugin, giving you the ability to selectively exclude specific pages from appearing in the widget generated by Better Section Navigation. This per-page control is managed via a metabox on the post edit screen. Note: On activation, BSN will automatically import the list of “excluded pages” set via that plugin, so you don’t have to manually re-assign excludes pages before deactivating the old one. Compatible with WordPress Multisite. This plugin started life as Simple Section Navigation Widget, but since that plugin hasn’t been updated in a while, we’ve taken up the reins with the goal of keeping it up to date with the latest WordPress conventions (i.e. getting rid of deprecation warnings) and adding a few nice-to-have features while retaining some of the simplicity of the original plugin. Simple Section Navigation Widget is incompatible with PHP 8.x, so as of October 2022, Better Section Navigation is now a drop-in replacement for Simple Section Navigation Widget. If you’ve been using Simple Section Navigation, you can now use this one instead without changing any settings! NOTE: Deactivate Simple Section Navigation Widget before activating Better Section Navigation.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C