CVE-2022-50954
Published
CVSS v3
6.2
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
WordPress Plugin cab-fare-calculator 1.0.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the controller parameter in tblight.php. Attackers can supply path traversal sequences through the controller GET parameter to include arbitrary files outside the intended controllers directory.
<p>Taxi Booking for WordPress is a feature-rich plugin designed for transportation services like taxis, limousines, and airport shuttles. It allows businesses to easily integrate booking functionality into their WordPress websites, offering dynamic pricing, vehicle management, and route customization.</p>
<p>Benefits for your business:<br />
Flexibility: Adapts to a range of transport needs with support for dynamic or fixed pricing.<br />
Customization: Pro features like multi-language support, multiple payment gateways, and editable email templates ensure it fits various business models.<br />
User-Friendly Management: A clean back-end interface simplifies vehicle and route configuration.</p>
<p>To overcome the learning curve, the plugin provides comprehensive documentation, including step-by-step guides for setting up points of interest (POIs), fixed fare routes, and email notifications.<br />
For additional support, you can access a ticket system at <a href="https://kanev.com/support/taxi-booking-for-wordpress" rel="nofollow ugc">kanev.com</a> available for both Free and Pro users.</p>
<p>For more details, check the official <a href="https://kanev.com/docs/taxi-booking-for-wordpress/73-taxi-booking-for-wordpress" rel="nofollow ugc">documentation</a> or explore the demo.</p>
<p>See <a href="https://tbwp.kanev.com/book-now" rel="nofollow ugc">Taxi Booking for WordPress demo</a> here. Contact us to get a back end demo access.</p>
<p><a href="https://kanev.com/products/taxi-booking-for-wordpress" rel="nofollow ugc">Get Taxi Booking Pro for WordPress here</a>.</p>
<p>With the Pro version of the plugin you get multiple payment gateways, translation into any language, custom fields to collect more information or upsell products or services.</p>