Extension WordPress
Vulnérabilités Five Star Business Profile and Schema
Cette page rassemble les failles publiées pour Five Star Business Profile and Schema, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Five Star Business Profile and Schema
2 fiches
Five Star Business Profile and Schema <= 2.3.19 – Authenticated (Editor+) Arbitrary Code Execution
The Five Star Business Profile and Schema plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.3.19. This makes it possible for authenticated attackers, with Editor-level access and above, to execute…
*-2.3.19
2.3.20
30/06/2026
Five Star Business Profile and Schema <= 2.1.6 – Subscriber+ Page Creation & Settings Update to Stored Cross-Site Scripting
The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to…
*-2.1.6
2.1.7
18/01/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.