Description
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
Published: 2026-07-02
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Five Star Business Profile and Schema plugin for WordPress contains a flaw in its editor module that permits an authenticated user with editor-level privileges to inject and execute arbitrary PHP code. This vulnerability is classified as CWE-94 and enables an attacker to fully compromise the WordPress site’s filesystem and database, potentially exfiltrating data, modifying content, or installing back‑doors, thereby affecting confidentiality, integrity, and availability.

Affected Systems

All installations of the Rustaurius Five Star Business Profile and Schema plugin, versions 2.3.19 or earlier, are affected. The plugin is widely deployed on WordPress sites to manage business information and schema markup, making it relevant to many production environments.

Risk and Exploitability

The CVSS score of 9.1 marks this vulnerability as critical, while an EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalogue. An attacker can trigger the exploit by logging into the WordPress site with editor or higher privileges and submitting malicious content through the plugin’s editor interface. The attack vector is therefore considered local to the site and requires active editor accounts, as inferred from the description.

Generated by OpenCVE AI on July 31, 2026 at 15:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Rustaurius Five Star Business Profile and Schema to the latest available version, which removes the code injection flaw.
  • If an upgrade is not immediately possible, limit editor permissions to trusted staff only and disable or remove the editor functionality of the plugin.
  • Consider disabling the plugin entirely if it is not required for the site’s functionality, or replace it with a more secure alternative.

Generated by OpenCVE AI on July 31, 2026 at 15:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
Title WordPress Five Star Business Profile and Schema plugin <= 2.3.19 - Arbitrary Code Execution vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T15:53:38.941Z

Reserved: 2026-02-19T09:52:39.681Z

Link: CVE-2026-27436

cve-icon Vulnrichment

Updated: 2026-07-02T13:39:01.480Z

cve-icon NVD

Status : Deferred

Published: 2026-07-02T12:17:01.073

Modified: 2026-07-02T16:16:30.353

Link: CVE-2026-27436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T15:15:02Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')