{"id":"CVE-2025-15698","published":"2026-09-19T07:16:31.313","lastModified":"2026-09-21T13:34:57.127","description":"The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","cvssScore":3.5,"cvssSeverity":"LOW","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/c6aa25a4-c795-47e6-9d09-bebe4afc1a08/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}