CVE-2026-86817: Unknown Five Star Business Profile And Schema

Medium severity, CVSS 4.9. EPSS: 0.2% chance of exploitation in the next 30 days.

The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and arbitrary site option values, in public output readable by unauthenticated visitors.

Affected products

  • Unknown Five Star Business Profile And Schema: from 2.3.20, before 2.4.0 (fixed in 2.4.0)

Published 2026-10-04. Last modified 2026-10-06.