### [CVE-2021-25060](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25060) ![](https://img.shields.io/static/v1?label=Product&message=Five%20Star%20Business%20Profile%20and%20Schema&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=2.1.7%3C%202.1.7%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-79%20Cross-site%20Scripting%20(XSS)&color=brighgreen) ### Description The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of sanitisation, it also lead to Stored Cross-Site Scripting issues ### POC #### Reference - https://wpscan.com/vulnerability/9e1ac711-1f65-49fa-b007-66170a77b265 #### Github No PoCs found on GitHub currently.