


Perceptive Security
SOC/SIEM Consultancy

Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
Published:
1 juli 2026 om 22:00:00
Alert date:
2 juli 2026 om 13:04:10
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
CVE-2026-27436 describes an Arbitrary Code Execution vulnerability affecting the Five Star Business Profile and Schema WordPress plugin in versions 2.3.19 and below. The vulnerability can be exploited by users with Editor-level access, allowing them to execute arbitrary code on the affected WordPress installation. This type of vulnerability poses a significant risk as it could lead to full site compromise, data theft, or further lateral movement. The issue has been reported via both the NVD and Patchstack vulnerability databases. WordPress site administrators running the affected plugin version are advised to update immediately to a patched version. The vulnerability is classified with a high severity rating.
Technical details
Mitigation steps:
Affected products:
Five Star Business Profile and Schema WordPress Plugin <= 2.3.19
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-27436
https://patchstack.com/database/wordpress/plugin/business-profile/vulnerability/wordpress-five-star-business-profile-and-schema-plugin-2-3-19-arbitrary-code-execution-vulnerability?_s_id=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
