Local File Inclusion Vulnerability in cab-fare-calculator Plugin by WordPress
CVE-2022-50954
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 10 May 2026
Badges
What is CVE-2022-50954?
The cab-fare-calculator plugin version 1.0.3 for WordPress is vulnerable to local file inclusion, allowing unauthenticated users to access arbitrary files on the server. By exploiting the controller parameter in tblight.php, attackers can introduce path traversal sequences, enabling them to include and execute files resides outside of the designated controller directory. This vulnerability poses a significant risk, as it can lead to unauthorized access to sensitive system files and data.
Affected Version(s)
cab-fare-calculator 1.0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved