CVE-2026-27436
Deferred Deferred - Pending Action

Editor Arbitrary Code Execution in Five Star Business Profile

Vulnerability report for CVE-2026-27436, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-02

Last updated on: 2026-07-02

Assigner: Patchstack

Description

Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-02
Last Modified
2026-07-02
Generated
2026-07-02
AI Q&A
2026-07-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
patchstack five_star_business_profile_and_schema_plugin to 2.3.19 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WordPress Five Star Business Profile and Schema Plugin, versions 2.3.19 and below, contains a vulnerability that allows arbitrary code execution. This means that an attacker can remotely run harmful code on websites using these plugin versions.

This vulnerability is classified as medium-priority with a high CVSS score of 9.1, indicating it is severe and can be exploited remotely without user interaction.

It falls under the OWASP Top 10 category A3: Injection, which involves injecting malicious code into an application.

Impact Analysis

This vulnerability allows attackers to remotely execute harmful code on affected websites, which can lead to complete compromise of the site.

  • Attackers could take control of the website.
  • Sensitive data could be stolen or manipulated.
  • The website could be used to launch further attacks or host malicious content.

There is a significant risk of mass exploitation campaigns targeting thousands of sites using this plugin version.

No official patch is currently available, so immediate mitigation or updates are strongly advised.

Mitigation Strategies

The vulnerability affects the WordPress Five Star Business Profile and Schema Plugin versions 2.3.19 and below, allowing remote arbitrary code execution.

Immediate mitigation steps include updating the plugin to a newer version if available or applying the mitigation rule provided by Patchstack to block attacks until an official patch is released.

If updating is not possible, seek assistance from your hosting provider or a developer to implement the mitigation rule and monitor your site for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-27436. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart