WordPress · Business Name Generator · CVE-2025-15698
**Name of the Vulnerable Software and Affected Versions**
Business Name Generator WordPress plugin versions prior to 1.4
**Description**
Insufficient sanitization and escaping of certain settings allow high-privilege users, such as administrators, to execute Stored Cross-Site Scripting (XSS) attacks. This issue persists even in environments where the `unfiltered html` capability is disabled, such as in multisite configurations. Stored Cross-Site Scripting occurs when a malicious script is permanently stored on the target server and served to other users.
**Recommendations**
Update the Business Name Generator WordPress plugin to version 1.4 or later.