CVE-2026-86817

NONE
Updated Oct 04, 2026
Unknown
Parameter Value
Affected Versions before 2.4.0
Type CWE-200 Information Exposure
Vendor Unknown
Public PoC No

The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and arbitrary site option values, in public output readable by unauthenticated visitors.

Weakness Type (CWE)

Vulnerable Products

unknown:five star business profile and schema