CVE-2025-15698: Business Name Generator <= 1.3 - Admin+ Stored XSS via Button Color Setting
The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
Which deployments are most exposed to this issue?
Multisite WordPress deployments are specifically relevant because they may disallow the unfiltered_html capability. The issue can still be exploited by high-privilege users such as administrators in that configuration.
What level of access does an attacker need?
An attacker needs high-privilege WordPress access, such as administrator access, to modify the affected plugin settings. The available information identifies the Button Color setting as the injection point.
Are versions later than 1.3 affected?
The issue is reported in the Business Name Generator plugin through version 1.3. No information is provided about versions after 1.3.