Description
The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Published: 2026-09-19
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Assess Impact
AI Analysis

Impact

The Business Name Generator WordPress plugin, version 1.3 and earlier, does not sanitize input in its button colour setting. An administrator who is able to modify that setting can store malicious JavaScript code that is later rendered in the browser when other users view the plugin pages, enabling a stored cross‑site scripting attack.

Affected Systems

WordPress sites running the Business Name Generator plugin version 1.3 or earlier. The plugin is identified in the CVE data as Unknown:Business Name Generator and is distributed under the name Business Name Generator for WordPress. No other vendors or products are listed as affected.

Risk and Exploitability

The CVSS score is 3.5, and the EPSS score is below 1 %, indicating a low overall likelihood of widespread exploitation. The vulnerability remains exploitable for any user who achieves administrative privileges, and the flaw persists even when the unfiltered_html capability is disabled. The issue is not listed in the CISA KEV catalog, so no publicly known exploitation activity is documented.

Generated by OpenCVE AI on September 20, 2026 at 00:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check the vendor’s website or the WordPress plugin repository for an updated release that corrects this issue and upgrade the plugin to that version.
  • If no update is available, temporarily neutralise the flaw by disabling or removing the button colour setting within the plugin’s options or by editing the stored option value in the database to delete any potentially malicious content.
  • Limit the number of administrator accounts and audit administrative privileges regularly so that only trusted users can modify plugin settings.

Generated by OpenCVE AI on September 20, 2026 at 00:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions business Name Generator
Vendors & Products Wordpress-extensions
Wordpress-extensions business Name Generator

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N'}


Sat, 19 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Title Business Name Generator <= 1.3 - Admin+ Stored XSS via Button Color Setting
References

Subscriptions

Wordpress-extensions Business Name Generator
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-19T13:20:56.703Z

Reserved: 2026-09-16T03:55:44.964Z

Link: CVE-2025-15698

cve-icon Vulnrichment

Updated: 2026-09-19T13:13:39.756Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T07:16:31.313

Modified: 2026-09-21T13:34:57.127

Link: CVE-2025-15698

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:44Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')