Impact
The Lesson Plan Book plugin for WordPress is vulnerable to a reflected cross‑site scripting flaw that results from the unsanitized use of the PHP superglobal `$_SERVER['PHP_SELF']`. An unauthenticated attacker can craft a URL that injects arbitrary JavaScript into the page output. When a victim clicks the malicious link, the script executes in the victim’s browser. This flaw may lead to disclosure of sensitive data or malicious manipulation of the page content.
Affected Systems
This flaw applies to all releases of the Lesson Plan Book plugin by the vendor burtrw up to and including version 1.3. There is no official patch or workaround listed at the time of this analysis, so the unmitigated risk remains for any site still running these affected releases.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.1, indicating a moderate severity, and an EPSS score of less than 1 %, implying a very low probability of exploitation as of now. It is not currently listed in the CISA KEV catalog. The attack can be performed remotely by simply clicking a malicious link; no authentication or privileged access is required. Administrators should treat this as a moderate risk that warrants timely remediation.
OpenCVE Enrichment