Impact
The Five Star Business Profile and Schema plugin contains a flaw in its editor component that permits an attacker with editor privileges to inject and execute arbitrary code. This vulnerability is identified as CWE-94, reflecting a code injection weakness that can compromise confidentiality, integrity, and availability by allowing full control over the server environment.
Affected Systems
All installations of the Rustaurius Five Star Business Profile and Schema plugin with version 2.3.19 or older are vulnerable. The usage of the plugin is inferred to be widespread within WordPress sites based on its presence in the WordPress plugin repository and known adoption by site owners to manage business information and schema markup.
Risk and Exploitability
The CVSS score of 9.1 classifies the flaw as critical, indicating a high potential for damage if exploited. The EPSS score is < 1%, indicating a very low probability of exploitation, and it is not listed in CISA's KEV catalog. Authenticated users who can edit content may trigger the exploit without additional access. The practical attack vector is therefore inferred to be via the editor, with prerequisites of possessing editor or higher WordPress capabilities.
OpenCVE Enrichment