Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 09 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Myasui
Myasui wp Vault Wordpress Wordpress wordpress |
|
| Vendors & Products |
Myasui
Myasui wp Vault Wordpress Wordpress wordpress |
Tue, 09 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting an unescaped parameter in the include functionality. Attackers can supply directory traversal sequences through the wpv-image GET parameter to access sensitive files like system configuration and credentials. | |
| Title | WP Vault 0.8.6.6 Local File Inclusion via wpv-image Parameter | |
| Weaknesses | CWE-98 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-09T13:16:31.313Z
Reserved: 2026-06-09T11:39:35.346Z
Link: CVE-2016-20064
Updated: 2026-06-09T13:16:26.112Z
Status : Deferred
Published: 2026-06-09T13:16:33.640
Modified: 2026-06-09T13:51:18.770
Link: CVE-2016-20064
No data.
OpenCVE Enrichment
Updated: 2026-06-09T20:20:59Z