CVE WATCH / VULNERABILITY DETAIL

CVE-2026-86817

UNKNOWNCVSS 0NVD feed

Published 4 October 2026 · tracked since 4 October 2026

Description

The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-86817 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-86817

UNKNOWNCVSS 0NVD feed

Published 4 October 2026 · tracked since 4 October 2026

Description

The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]