Impact
The Five Star Business Profile and Schema WordPress plugin, versions prior to 2.4.0, fails to enforce access controls on callback functions that resolve schema field default values. As a consequence, an authenticated user holding an Author role or higher can input data that is later emitted as public content. When this data includes sensitive material such as other users' password hashes or arbitrary site option values, it becomes readable by unauthenticated visitors, resulting in accidental leakage of confidential information. This disclosure vulnerability is classified as a sensitive data exposure flaw that can compromise the confidentiality of site users and site configuration.
Affected Systems
The affected product is the Five Star Business Profile and Schema WordPress plugin, specifically releases 2.3.20 and 2.3.21. The vulnerability is present in all releases before 2.4.0; updating to version 2.4.0 or later mitigates the issue.
Risk and Exploitability
Although no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the impact is significant because an authenticated author can inject arbitrary data visible to the public. The CVSS score is not provided, but the exposure of password hashes and site options suggests a high confidentiality impact. The exploitation route requires an authorized editor or author account; attackers who can elevate permissions to that level or compromise such an account can deploy the vulnerable callbacks. In the absence of an official public exploit, the risk remains theoretical but non‑negligible given the exposure potential.
OpenCVE Enrichment