---
id: CVE-2025-13886
title: >-
  The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in
  all versions up to, and including, 1.1.1 via the 'template' parameter in the
  `book` shortcode due to insufficient path sanitization
summary: >-
  The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in
  all versions up to, and including, 1.1.1 via the 'template' parameter in the
  `book` shortcode due to insufficient path sanitization. This makes it possible
  fo…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-98
published: '2025-12-12'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13886'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/lt-unleashed/tags/1.1.1/lt-unleashed.php#L315
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/lt-unleashed/trunk/lt-unleashed.php#L241
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/lt-unleashed/trunk/lt-unleashed.php#L315
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/c72099cc-e70a-4afe-92c0-8f9f8c1e91b7?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00579
epssPercentile: 0.45547
ingestedAt: '2026-09-30T23:29:32.485Z'
---

## Overview

The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1 via the 'template' parameter in the `book` shortcode due to insufficient path sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where files such as wp-config.php can be included.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
