Extension WordPress

Vulnérabilités Five Star Business Profile and Schema

Cette page rassemble les failles publiées pour Five Star Business Profile and Schema, leurs plages de versions affectées et les correctifs signalés dans la base locale.

2Vulnérabilités
0Critiques
2Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Five Star Business Profile and Schema

2 fiches

CVE-2026-27436 Élevée · 7,2
Five Star Business Profile and Schema

Five Star Business Profile and Schema <= 2.3.19 – Authenticated (Editor+) Arbitrary Code Execution

The Five Star Business Profile and Schema plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.3.19. This makes it possible for authenticated attackers, with Editor-level access and above, to execute…

Versions affectées

*-2.3.19

Correctif

2.3.20

Publication

30/06/2026

CVE-2021-25060 Moyenne · 5,4
Five Star Business Profile and Schema

Five Star Business Profile and Schema <= 2.1.6 – Subscriber+ Page Creation & Settings Update to Stored Cross-Site Scripting

The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to…

Versions affectées

*-2.1.6

Correctif

2.1.7

Publication

18/01/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités