


Perceptive Security
SOC/SIEM Consultancy

Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
Published:
1 juli 2026 om 22:00:00
Alert date:
2 juli 2026 om 14:04:37
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
CVE-2026-27436 describes an Arbitrary Code Execution vulnerability affecting the Five Star Business Profile and Schema WordPress plugin in versions 2.3.19 and below. The vulnerability allows users with Editor-level privileges to execute arbitrary code on affected WordPress installations. It was reported via PatchStack and published on the NVD. The flaw poses a high risk to WordPress sites using the affected plugin versions. Site administrators are advised to update to a patched version immediately. No additional technical details or proof-of-concept code are provided in the available description. The vulnerability is classified as high severity given the nature of arbitrary code execution.
Technical details
Mitigation steps:
Affected products:
Five Star Business Profile and Schema WordPress Plugin <= 2.3.19
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-27436
https://patchstack.com/database/wordpress/plugin/business-profile/vulnerability/wordpress-five-star-business-profile-and-schema-plugin-2-3-19-arbitrary-code-execution-vulnerability?_s_id=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
