CVE-2022-1391
Cab fare calculator < 1.0.4 - Unauthenticated LFI
Record summary
CVE-2022-1391 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 9, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Cab fare calculator | CVE List | 1.0.4 to < 1.0.4 | affected |
cab_fare_calculatorBrowse kanev / cab_fare_calculator | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALWordPress Cab fare calculator < 1.0.4 - Local File InclusionCVSS 9.8
The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.
Impact
An attacker can exploit this vulnerability to read sensitive files on the server, potentially exposing sensitive information.
Remediation
Update to the latest version of the WordPress Cab fare calculator plugin (1.0.4) to fix the local file inclusion vulnerability.
Source: ProjectDiscovery