The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Aug 2025 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Latepoint
Latepoint latepoint |
|
Vendors & Products |
Latepoint
Latepoint latepoint |
Wed, 13 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 13 Aug 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files. | |
Title | Latepoint < 5.1.94 - Unauthenticated LFI | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-08-13T06:00:02.587Z
Updated: 2025-08-13T16:02:40.135Z
Reserved: 2025-06-26T13:15:47.093Z
Link: CVE-2025-6715

Updated: 2025-08-13T14:03:25.278Z

Status : Awaiting Analysis
Published: 2025-08-13T06:15:26.537
Modified: 2025-08-13T17:33:46.673
Link: CVE-2025-6715

No data.