← back
CVE-2016-20064

WP Vault 0.8.6.6 Local File Inclusion via wpv-image Parameter

CVSS 6.9 MEDIUMEPSS 0.7%CWE-98
Vexday Risk Score
33Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 6.9EPSS 0.7%KEV nãoPoC públicaNuclei Metasploit Patch
Lifecycle
09 Jun 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting an unescaped parameter in the include functionality. Attackers can supply directory traversal sequences through the wpv-image GET parameter to access sensitive files like system configuration and credentials.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
myasui · WP Vault
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →