Description
The Simple Business Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'simple_business_data' shortcode attributes in all versions up to, and including, 1.0.1. This is due to the plugin not properly sanitizing user input or escaping output when embedding the `type` attribute into the `class` attribute in rendered HTML. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2025-10-22
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross-Site Scripting
Action: Apply Patch
AI Analysis

Impact

A stored cross‑site scripting flaw exists in the Simple Business Data WordPress plugin. The plugin fails to sanitize or escape the value of the 'type' attribute used in the 'simple_business_data' shortcode, embedding the content directly into the class attribute of rendered HTML. An attacker who can create or edit content with contributor-level or higher access can inject arbitrary JavaScript that will execute in the browsers of any user who visits a page containing the compromised shortcode. The script runs client‑side and may be used to steal session cookies, redirect users, or perform other malicious actions within the context of the victim’s authenticated session.

Affected Systems

The vulnerability affects the Simple Business Data plugin developed by dmbarber, installed in WordPress sites. All released plugin versions up to and including 1.0.1 are impacted; newer releases beyond 1.0.1 are not listed as affected.

Risk and Exploitability

The CVSS score for this issue is 6.4, indicating moderate severity. The EPSS score is reported as less than 1%, reflecting a low probability of exploitation within the current timeframe, and the vulnerability is not yet listed in CISA’s KEV catalog. Exploitation requires an authenticated user with contributor or higher privileges, but the resulting XSS can affect any visitor to the compromised page. Overall, the risk is moderate, with low likelihood but potentially significant impact on users of the site.

Generated by OpenCVE AI on April 21, 2026 at 02:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Simple Business Data plugin to a version that removes the XSS flaw.
  • If an upgrade is not immediately available, disable or remove the plugin or prohibit the use of its 'simple_business_data' shortcode.
  • Limit contributor-level access to trusted users and monitor for anomalous script activity.
  • While an official workaround is not provided, any attempt to escape or remove the 'type' attribute value from output could mitigate the risk until a patch is applied.

Generated by OpenCVE AI on April 21, 2026 at 02:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Dmbarber
Dmbarber simple Business Data
Wordpress
Wordpress wordpress
Vendors & Products Dmbarber
Dmbarber simple Business Data
Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Oct 2025 08:45:00 +0000

Type Values Removed Values Added
Description The Simple Business Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'simple_business_data' shortcode attributes in all versions up to, and including, 1.0.1. This is due to the plugin not properly sanitizing user input or escaping output when embedding the `type` attribute into the `class` attribute in rendered HTML. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Simple Business Data <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Dmbarber Simple Business Data
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:18:52.071Z

Reserved: 2025-10-16T15:04:49.136Z

Link: CVE-2025-11870

cve-icon Vulnrichment

Updated: 2025-10-22T14:20:12.185Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T09:15:35.320

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-11870

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T02:15:06Z

Weaknesses