{"id":"CVE-2025-15698","title":"The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html…","summary":"The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html…","severity":"low","cvss":3.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N","cwe":["CWE-79"],"product":"Business Name Generator","affected":["business_name_generator <= 1.3"],"published":"2026-09-19","updated":"2026-09-21","sourceUpdated":"2026-09-21T13:34:57.127","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-15698","references":[{"url":"https://wpscan.com/vulnerability/c6aa25a4-c795-47e6-9d09-bebe4afc1a08/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"epss":0.00142,"epssPercentile":0.03902,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-19T13:15:28.847415Z"},"ingestedAt":"2026-09-19T06:59:13.119Z","slug":"CVE-2025-15698","body":"## Overview\n\nThe Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":19,"depthScoreParts":{"impact":19.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":207686,"id":"CVE-2025-15698","ts":1789826663570,"field":"cvss","old":null,"new":"3.5"},{"seq":207685,"id":"CVE-2025-15698","ts":1789826663570,"field":"severity","old":"none","new":"low"}]}