Record summary

CVE-2022-50954 has a selected CVSS score of 6.9 (medium); EIP currently links 1 catalogued exploit.

Description

WordPress Plugin cab-fare-calculator 1.0.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the controller parameter in tblight.php. Attackers can supply path traversal sequences through the controller GET parameter to include arbitrary files outside the intended controllers directory.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 11, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.0.3affected

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin cab-fare-calculator 1.0.3 - Local File InclusionExploitDB exploitby Hassan Khan YusufzaiNot analyzed1 file
ExploitDB

PoC details

References

4