Five Star Business Profile and Schema
by WordPress
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-25060 | Med | 0.35 | 5.4 | 0.01 | Feb 21, 2022 | The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them.… | ||
| CVE-2026-27436 | Cri | 0.00 | 9.1 | 0.01 | Jul 2, 2026 | Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions. |
- risk 0.35cvss 5.4epss 0.01
The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them.…
- risk 0.00cvss 9.1epss 0.01
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.