CVE detail
CVE-2021-25060 — CVE-2021-25060
Published 2022-02-21 · Modified 2026-06-17 · Vendor fivestarplugins · Product five_star_business_profile_and_schema · Source nvd
MEDIUM
severity
CVSS-derived band
0.0060
EPSS probability
exploitation probability, 30d
45.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of sanitisation, it also lead to Stored Cross-Site Scripting issues
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References