Record summary

CVE-2022-1391 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 9, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Cab fare calculator

CVE List1.0.4 to < 1.0.4affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress Cab fare calculator < 1.0.4 - Local File InclusionCVSS 9.8

The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.

Impact

An attacker can exploit this vulnerability to read sensitive files on the server, potentially exposing sensitive information.

Remediation

Update to the latest version of the WordPress Cab fare calculator plugin (1.0.4) to fix the local file inclusion vulnerability.

WeaknessesCWE-22
AuthorsSplint3r7
Template tagscvecve2022wordpresswp-pluginlfiwpedbwpscankanevvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:kanev:cab_fare_calculator:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3