WP Vault <= 0.8.6.6 - Local File Inclusion
mediumThe WP Vault plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.8.6.6 via the 'wpv-image' parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass a...
- CVSS:
- 5.3
- Affected:
- up to 0.8.6.6
- Fix:
- No patched version reported
- Disclosed:
- Nov 30, 2016