PT-2025-32966 · WordPress · Latepoint Wordpress Plugin

Wesley

·

Published

2025-08-13

·

Updated

2025-08-18

·

CVE-2025-6715

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: LatePoint WordPress plugin versions prior to 5.1.94
Description: The LatePoint WordPress plugin is susceptible to a Local File Inclusion issue via the layout parameter. This allows attackers to include and execute PHP files on the server, potentially enabling the execution of arbitrary PHP code.
Recommendations: Update the LatePoint WordPress plugin to version 5.1.94 or later.

Exploit

Fix

Related Identifiers

CVE-2025-6715

Affected Products

Latepoint Wordpress Plugin