Impact
The Business Name Generator WordPress plugin, version 1.3 and earlier, does not sanitize input in its button colour setting. An administrator who is able to modify that setting can store malicious JavaScript code that is later rendered in the browser when other users view the plugin pages, enabling a stored cross‑site scripting attack.
Affected Systems
WordPress sites running the Business Name Generator plugin version 1.3 or earlier. The plugin is identified in the CVE data as Unknown:Business Name Generator and is distributed under the name Business Name Generator for WordPress. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score is 3.5, and the EPSS score is below 1 %, indicating a low overall likelihood of widespread exploitation. The vulnerability remains exploitable for any user who achieves administrative privileges, and the flaw persists even when the unfiltered_html capability is disabled. The issue is not listed in the CISA KEV catalog, so no publicly known exploitation activity is documented.
OpenCVE Enrichment