Record summary

CVE-2025-6715 has a selected CVSS score of 9.8 (critical).

Description

The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 13, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

LatePoint

Default status: unaffected

CVE ListBefore 5.1.94affected

References

2