Description
The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and arbitrary site option values, in public output readable by unauthenticated visitors.
Published: 2026-10-04
Score: n/a
EPSS: n/a
KEV: No
Impact: Sensitive Data Disclosure
Action: Apply Update
AI Analysis

Impact

The Five Star Business Profile and Schema WordPress plugin, versions prior to 2.4.0, fails to enforce access controls on callback functions that resolve schema field default values. As a consequence, an authenticated user holding an Author role or higher can input data that is later emitted as public content. When this data includes sensitive material such as other users' password hashes or arbitrary site option values, it becomes readable by unauthenticated visitors, resulting in accidental leakage of confidential information. This disclosure vulnerability is classified as a sensitive data exposure flaw that can compromise the confidentiality of site users and site configuration.

Affected Systems

The affected product is the Five Star Business Profile and Schema WordPress plugin, specifically releases 2.3.20 and 2.3.21. The vulnerability is present in all releases before 2.4.0; updating to version 2.4.0 or later mitigates the issue.

Risk and Exploitability

Although no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the impact is significant because an authenticated author can inject arbitrary data visible to the public. The CVSS score is not provided, but the exposure of password hashes and site options suggests a high confidentiality impact. The exploitation route requires an authorized editor or author account; attackers who can elevate permissions to that level or compromise such an account can deploy the vulnerable callbacks. In the absence of an official public exploit, the risk remains theoretical but non‑negligible given the exposure potential.

Generated by OpenCVE AI on October 4, 2026 at 07:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Five Star Business Profile and Schema plugin to version 2.4.0 or later to eliminate the privilege‑controlled callback issue.
  • Verify that no custom or deprecated callback functions are still enabled in the plugin configuration; disable or remove any override mechanisms that allow arbitrary data setting.
  • Review public pages or content generated by the plugin for any exposed sensitive values, such as password hashes or site options, and cleanse or redact them if found.
  • Limit author or editor role permissions to the minimum necessary for content creation, ensuring no unauthorized access to the plugin’s schema settings.

Generated by OpenCVE AI on October 4, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Sun, 04 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and arbitrary site option values, in public output readable by unauthenticated visitors.
Title Five Star Business Profile and Schema 2.3.20 - 2.3.21 - Author+ Sensitive Data Disclosure via Schema Field Default Callback
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-04T06:00:23.722Z

Reserved: 2026-09-08T13:52:58.085Z

Link: CVE-2026-86817

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T07:16:34.053

Modified: 2026-10-04T07:16:34.053

Link: CVE-2026-86817

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T07:30:09Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control