Five Star Business Profile and Schema <= 2.3.19 - Authenticated (Editor+) Arbitrary Code Execution
high
The Five Star Business Profile and Schema plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.3.19. This makes it possible for authenticated attackers, with Editor-level access and above, to execute code on the server.
- CVSS:
- 7.2
- Affected:
- up to 2.3.19
- Fixed in:
- 2.3.20
- Disclosed:
- Jun 30, 2026
CVE-2026-27436 on NVD →
Five Star Business Profile and Schema <= 2.1.6 - Subscriber+ Page Creation & Settings Update to Stored Cross-Site Scripting
medium
The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of sanitisation,...
- CVSS:
- 5.4
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.7
- Disclosed:
- Jan 18, 2022
CVE-2021-25060 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database