Unrated severityNVD Advisory· Published Oct 4, 2026
CVE-2026-86817
CVE-2026-86817
Description
The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and arbitrary site option values, in public output readable by unauthenticated visitors.
Affected products
1- Range: <2.4.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.