Ad

CVE-2026-86817

NONE
Обновлено 4 октября 2026
WordPress
Параметр Значение
Уязвимые версии до 2.4.0
Тип уязвимости CWE-200 Information Exposure
Поставщик WordPress
Публичный эксплойт Нет

The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and arbitrary site option values, in public output readable by unauthenticated visitors.

Тип уязвимости (CWE)

Уязвимые продукты

unknown:five star business profile and schema