Back

CRITICAL

Latepoint < 5.1.94 - Unauthenticated LFI

Published Aug 13, 2025

Description

The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Aug 13, 2025
Updated Aug 13, 2025
Reserved Jun 26, 2025
CISA Vulnrichment
Updated Aug 13, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a