VYPR
Medium severity6.2NVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026No known patch

CVE-2016-20064

CVE-2016-20064

Description

WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting an unescaped parameter in the include functionality. Attackers can supply directory traversal sequences through the wpv-image GET parameter to access sensitive files like system configuration and credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.

CVE-2016-20064 · Medium · VYPR