{"id":"CVE-2026-86817","title":"The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input …","summary":"The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input …","severity":"none","cwe":["CWE-200"],"product":"Five Star Business Profile and Schema","affected":["five_star_business_profile_and_schema >= 2.3.20 < 2.4.0"],"published":"2026-10-04","updated":"2026-10-04","sourceUpdated":"2026-10-04T07:16:34.053","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86817","references":[{"url":"https://wpscan.com/vulnerability/2a400958-7ed8-4358-a46a-2b8e0716a771/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-04T06:55:02.312Z","slug":"CVE-2026-86817","body":"## Overview\n\nThe Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and arbitrary site option values, in public output readable by unauthenticated visitors.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}