plugin

Business Profile Vulnerabilities

2 known security issues reported for the Business Profile WordPress plugin. Most recent disclosed Jun 30, 2026.

1 high 1 medium

Running Business Profile on your site? Check whether your installed version is affected.

Scan your site free

Five Star Business Profile and Schema <= 2.3.19 - Authenticated (Editor+) Arbitrary Code Execution

high

The Five Star Business Profile and Schema plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.3.19. This makes it possible for authenticated attackers, with Editor-level access and above, to execute code on the server.

CVSS:
7.2
Affected:
up to 2.3.19
Fixed in:
2.3.20
Disclosed:
Jun 30, 2026

CVE-2026-27436 on NVD →

Five Star Business Profile and Schema <= 2.1.6 - Subscriber+ Page Creation & Settings Update to Stored Cross-Site Scripting

medium

The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of sanitisation,...

CVSS:
5.4
Affected:
up to 2.1.6
Fixed in:
2.1.7
Disclosed:
Jan 18, 2022

CVE-2021-25060 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database