← back
CVE-2022-1391observed exploitationCWE-22

Cab fare calculator < 1.0.4 - Unauthenticated LFI

45Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 14%
from disclosure to weapon
Published on NVDApr 25
VulnCheck+1141d
exploitation probability
14%top 4% of all CVEs
observed exploitation
yesVulnCheck
The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.