Impact
The Five Star Business Profile and Schema plugin for WordPress contains a flaw in its editor module that permits an authenticated user with editor-level privileges to inject and execute arbitrary PHP code. This vulnerability is classified as CWE-94 and enables an attacker to fully compromise the WordPress site’s filesystem and database, potentially exfiltrating data, modifying content, or installing back‑doors, thereby affecting confidentiality, integrity, and availability.
Affected Systems
All installations of the Rustaurius Five Star Business Profile and Schema plugin, versions 2.3.19 or earlier, are affected. The plugin is widely deployed on WordPress sites to manage business information and schema markup, making it relevant to many production environments.
Risk and Exploitability
The CVSS score of 9.1 marks this vulnerability as critical, while an EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalogue. An attacker can trigger the exploit by logging into the WordPress site with editor or higher privileges and submitting malicious content through the plugin’s editor interface. The attack vector is therefore considered local to the site and requires active editor accounts, as inferred from the description.
OpenCVE Enrichment