CVE-2025-6715: Latepoint < 5.1.94 - Unauthenticated LFI
Published Aug 13, 2025
·Updated
The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.
Affected Software
1 affected component
Latepoint LatePoint WordPress Plugin<5.1.94
Event History
Aug 13, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-6715?
CVE-2025-6715 is considered a high severity vulnerability due to its potential for local file inclusion and remote code execution.
2
How do I fix CVE-2025-6715?
To fix CVE-2025-6715, update the LatePoint WordPress plugin to version 5.1.94 or later.
3
What is the Vulnerability type of CVE-2025-6715?
CVE-2025-6715 is categorized as a Local File Inclusion vulnerability.
4
What can attackers do with CVE-2025-6715?
Attackers can use CVE-2025-6715 to include and execute arbitrary PHP files on the vulnerable server.
5
Which versions of the LatePoint plugin are affected by CVE-2025-6715?
CVE-2025-6715 affects all versions of the LatePoint WordPress plugin before 5.1.94.