Description
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
Published: 2026-07-02
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Five Star Business Profile and Schema plugin contains a flaw in its editor component that permits an attacker with editor privileges to inject and execute arbitrary code. This vulnerability is identified as CWE-94, reflecting a code injection weakness that can compromise confidentiality, integrity, and availability by allowing full control over the server environment.

Affected Systems

All installations of the Rustaurius Five Star Business Profile and Schema plugin with version 2.3.19 or older are vulnerable. The usage of the plugin is inferred to be widespread within WordPress sites based on its presence in the WordPress plugin repository and known adoption by site owners to manage business information and schema markup.

Risk and Exploitability

The CVSS score of 9.1 classifies the flaw as critical, indicating a high potential for damage if exploited. The EPSS score is < 1%, indicating a very low probability of exploitation, and it is not listed in CISA's KEV catalog. Authenticated users who can edit content may trigger the exploit without additional access. The practical attack vector is therefore inferred to be via the editor, with prerequisites of possessing editor or higher WordPress capabilities.

Generated by OpenCVE AI on July 21, 2026 at 12:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Rustaurius Five Star Business Profile and Schema to the latest version that contains the fix.
  • Apply input validation and sanitization in the editor to mitigate the CWE-94 code injection weakness.
  • If the plugin is not needed, deactivate or uninstall it to remove the vulnerability.
  • Restrict WordPress editor privileges to trusted users only, enforcing prevent unauthorized content editing.

Generated by OpenCVE AI on July 21, 2026 at 12:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
Title WordPress Five Star Business Profile and Schema plugin <= 2.3.19 - Arbitrary Code Execution vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T15:53:38.941Z

Reserved: 2026-02-19T09:52:39.681Z

Link: CVE-2026-27436

cve-icon Vulnrichment

Updated: 2026-07-02T13:39:01.480Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:15:02Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')