---
id: CVE-2026-86817
title: >-
  The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does
  not properly restrict the callbacks used to resolve schema field default
  values, allowing authenticated users with Author-level access and above to
  store input …
summary: >-
  The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does
  not properly restrict the callbacks used to resolve schema field default
  values, allowing authenticated users with Author-level access and above to
  store input …
severity: none
cwe:
  - CWE-200
product: Five Star Business Profile and Schema
affected:
  - five_star_business_profile_and_schema >= 2.3.20 < 2.4.0
published: '2026-10-04'
updated: '2026-10-04'
sourceUpdated: '2026-10-04T07:16:34.053'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86817'
references:
  - url: 'https://wpscan.com/vulnerability/2a400958-7ed8-4358-a46a-2b8e0716a771/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-04T06:55:02.312Z'
---

## Overview

The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and arbitrary site option values, in public output readable by unauthenticated visitors.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
