PT-2025-50801 · WordPress · Lt Unleashed
Published
2025-12-12
·
Updated
2025-12-17
·
CVE-2025-13886
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LT Unleashed plugin for WordPress versions up to and including 1.1.1
Description
The LT Unleashed plugin for WordPress is susceptible to Local File Inclusion due to inadequate path sanitization of the
template parameter within the book shortcode. This allows authenticated attackers with Contributor-level access or higher to include and execute arbitrary files on the server. Successful exploitation could lead to bypassing access controls, obtaining sensitive data, or achieving code execution, particularly if files like wp-config.php are included.Recommendations
Update the LT Unleashed plugin to a version beyond 1.1.1.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lt Unleashed