← back
CVE-2025-6715criticalobserved exploitation

Latepoint < 5.1.94 - Unauthenticated LFI

50Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 9.8epss 0.6%
from disclosure to weapon
Published on NVDAug 13
VulnCheckAug 13
exploitation probability
0.6%top 56% of all CVEs
observed exploitation
yesVulnCheck
The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · LatePoint