Arbitrary Code Execution in Five Star Business Profile Plugin by WordPress
CVE-2026-27436

9.1CRITICAL

What is CVE-2026-27436?

The Five Star Business Profile and Schema plugin for WordPress is vulnerable to arbitrary code execution, which could allow unauthorized users to execute malicious code on affected installations. This vulnerability impacts versions up to 2.3.19, making it crucial for website administrators to update to secure versions or apply necessary patches to mitigate potential risks. In an era where cyber threats are prevalent, ensuring your plugins are up to date is essential for maintaining site integrity.

Affected Version(s)

Five Star Business Profile and Schema <= 2.3.19

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo | Patchstack Bug Bounty Program
.