PT-2025-43053 · WordPress · Simple Business Data
Published
2025-10-22
·
Updated
2025-10-22
·
CVE-2025-11870
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Simple Business Data plugin for WordPress versions up to and including 1.0.1
Description
The Simple Business Data plugin for WordPress is susceptible to Stored Cross-Site Scripting through the 'simple business data' shortcode attributes. The issue arises from insufficient sanitization of user input and inadequate output escaping when the
type attribute is embedded into the class attribute within rendered HTML. This allows authenticated attackers with contributor-level access or higher to inject malicious web scripts into pages. These scripts will execute each time a user accesses the compromised page.Recommendations
Update the Simple Business Data plugin to a version beyond 1.0.1.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple Business Data