Answer in brief
CVE-2026-86817 records a Unknown severity vulnerability in Five Star Business Profile and Schema 2.3.20 - 2.3.21 - Author+ Sensitive Data Disclosure via Schema Field Default Callback. The current sources do not mark it as known exploited. The current feed maps Unknown/Five Star Business Profile and Schema (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Unknown/Five Star Business Profile and Schema (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Unknown/Five Star Business Profile and Schemageneric | >=2.3.20 <2.4.0 | 2.4.0 |
Published upstream
Oct 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 4, 2026
The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and arbitrary site option values, in public output readable by unauthenticated visitors.
Quoted source text, attributed separately from HOL analysis.