CVE-2016-20064
WP Vault 0.8.6.6 Local File Inclusion via wpv-image Parameter
Vexday Risk Score
33Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 6.9EPSS 0.7%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
09 Jun 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting an unescaped parameter in the include functionality. Attackers can supply directory traversal sequences through the wpv-image GET parameter to access sensitive files like system configuration and credentials.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
myasui · WP Vaultpublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/40850unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →