PT-2025-50801 · WordPress · Lt Unleashed

Published

2025-12-12

·

Updated

2025-12-17

·

CVE-2025-13886

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LT Unleashed plugin for WordPress versions up to and including 1.1.1
Description The LT Unleashed plugin for WordPress is susceptible to Local File Inclusion due to inadequate path sanitization of the template parameter within the book shortcode. This allows authenticated attackers with Contributor-level access or higher to include and execute arbitrary files on the server. Successful exploitation could lead to bypassing access controls, obtaining sensitive data, or achieving code execution, particularly if files like wp-config.php are included.
Recommendations Update the LT Unleashed plugin to a version beyond 1.1.1.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-13886

Affected Products

Lt Unleashed