The Lesson Plan Book plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Metrics
Affected Vendors & Products
References
History
Fri, 09 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Burtrw
Burtrw lesson Plan Book Wordpress Wordpress wordpress |
|
| Vendors & Products |
Burtrw
Burtrw lesson Plan Book Wordpress Wordpress wordpress |
Fri, 09 Jan 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Lesson Plan Book plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | |
| Title | Lesson Plan Book <= 1.3 - Reflected Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-01-09T11:15:30.823Z
Updated: 2026-01-09T14:51:20.686Z
Reserved: 2025-12-02T15:38:02.335Z
Link: CVE-2025-13893
Updated: 2026-01-09T14:51:16.638Z
Status : Received
Published: 2026-01-09T12:15:52.493
Modified: 2026-01-09T12:15:52.493
Link: CVE-2025-13893
No data.