nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-6715 CVE-2025-6715
CRITICAL
Latepoint < 5.1.94 - Unauthenticated LFI
Record summary
CVE-2025-6715 has a selected CVSS score of 9.8 (critical).
Description
The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 13, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
LatePoint WordPress pluginBrowse LatePoint / LatePoint WordPress plugin | VulnCheck | Version data not supplied | |
LatePointDefault status: unaffected | CVE List | Before 5.1.94 | affected |
References
2wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/357aba51-b65e-4691-864b-fef1c78a9362