CVE-2026-86817
Received
Received - Intake
Five Star Business Profile Schema XSS Vulnerability
Vulnerability report for CVE-2026-86817, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-04
Last updated on: 2026-10-04
Assigner: WPScan
Description
Description
The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and arbitrary site option values, in public output readable by unauthenticated visitors.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| five_star_business_profile_and_schema | 2.3.20 | * |
| five_star_business_profile_and_schema | 2.3.21 | From 2.3.20 (inc) to 2.4.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |