PT-2022-9616 · WordPress · Five Star Business Profile/Schema

Krzysztof Zając

·

Published

2022-02-21

·

Updated

2022-02-28

·

CVE-2021-25060

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Five Star Business Profile and Schema WordPress plugin versions prior to 2.1.7
Description The issue concerns the lack of authorization and CSRF protection in certain AJAX actions, specifically bpfwp welcome add contact page and bpfwp welcome set contact information, allowing any authenticated users to call them. Additionally, the lack of sanitization leads to Stored Cross-Site Scripting issues.
Recommendations For versions prior to 2.1.7, update to version 2.1.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the bpfwp welcome add contact page and bpfwp welcome set contact information AJAX actions to prevent exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25060

Affected Products

Five Star Business Profile/Schema