Arbitrary Code Execution in Five Star Business Profile Plugin by WordPress
CVE-2026-27436
9.1CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 July 2026
What is CVE-2026-27436?
The Five Star Business Profile and Schema plugin for WordPress is vulnerable to arbitrary code execution, which could allow unauthorized users to execute malicious code on affected installations. This vulnerability impacts versions up to 2.3.19, making it crucial for website administrators to update to secure versions or apply necessary patches to mitigate potential risks. In an era where cyber threats are prevalent, ensuring your plugins are up to date is essential for maintaining site integrity.
Affected Version(s)
Five Star Business Profile and Schema <= 2.3.19