CVE-2025-30836: WordPress LatePoint plugin <= 5.1.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LatePoint LatePoint latepoint allows Stored XSS.This issue affects LatePoint: from n/a through <= 5.1.6.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30836?
CVE-2025-30836 is considered a high-severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2025-30836?
To mitigate CVE-2025-30836, update the LatePoint plugin to version 5.1.7 or later, where the vulnerability is addressed.
What types of systems are affected by CVE-2025-30836?
CVE-2025-30836 affects the LatePoint application and the LatePoint WordPress plugin up to version 5.1.6.
What is the main issue with CVE-2025-30836?
The main issue with CVE-2025-30836 is improper neutralization of input during web page generation, leading to stored Cross-site Scripting (XSS) vulnerabilities.
Is there a workaround for CVE-2025-30836?
While updating is the best solution, a temporary workaround includes disabling user input fields on the affected web pages to prevent exploitation.