---
id: CVE-2025-15698
title: >-
  The Business Name Generator WordPress plugin through 1.3 does not sanitise and
  escape some of its settings, which could allow high privilege users such as
  admin to perform Stored Cross-Site Scripting attacks even when the
  unfiltered_html…
summary: >-
  The Business Name Generator WordPress plugin through 1.3 does not sanitise and
  escape some of its settings, which could allow high privilege users such as
  admin to perform Stored Cross-Site Scripting attacks even when the
  unfiltered_html…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N'
cwe:
  - CWE-79
product: Business Name Generator
affected:
  - business_name_generator <= 1.3
published: '2026-09-19'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:34:57.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15698'
references:
  - url: 'https://wpscan.com/vulnerability/c6aa25a4-c795-47e6-9d09-bebe4afc1a08/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00142
epssPercentile: 0.03917
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-19T13:15:28.847415Z'
ingestedAt: '2026-09-19T06:59:13.119Z'
---

## Overview

The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
