Executive brief
The Five Star Business Profile and Schema plugin for WordPress, which helps businesses manage their contact information and search engine visibility, contains a security flaw. An attacker with Editor-level permissions can exploit this vulnerability to run unauthorized commands on the website's server. This could lead to a complete takeover of the site, theft of sensitive data, or the installation of malicious software.
Technical details
An arbitrary code execution vulnerability exists in the Five Star Business Profile and Schema plugin for WordPress (versions up to and including 2.3.19). The flaw allows an authenticated user with 'Editor' role privileges to execute arbitrary PHP code on the server. This is classified as an injection-style vulnerability where input is likely processed without sufficient sanitization or restriction. While the attack requires high privileges (Editor), the impact is critical as it leads to full system compromise. As of the reporting date, no official patch has been released by the vendor.
Affected products
- Five Star Plugins Five Star Business Profile and Schema <= 2.3.19
Timeline
- 2025-10-13: other: Reported by researcher daroo
- 2026-06-30: advisory: Published by Patchstack
- 2026-07-02: disclosed: NVD publication date