plugin

Cab Fare Calculator Vulnerabilities

6 known security issues reported for the Cab Fare Calculator WordPress plugin. Most recent disclosed Jan 27, 2025.

2 medium

Running Cab Fare Calculator on your site? Check whether your installed version is affected.

Scan your site free

Cab fare calculator [cab-fare-calculator] <= 1.1 (unfixed)

unknown

[en] Missing Authorization vulnerability in Marian Kanev Cab fare calculator allows Stored XSS. This issue affects Cab fare calculator: from n/a through 1.1.

Affected:
up to 1.1
Fix:
No patched version reported
Disclosed:
Jan 27, 2025

CVE-2025-23982 on NVD →

Cab fare calculator [cab-fare-calculator] < 1.1.7

unknown

[en] The Cab fare calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vehicle title setting in versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arb...

Affected:
up to 1.1.7
Fixed in:
1.1.7
Disclosed:
Sep 5, 2024

CVE-2022-3556 on NVD →

Cab fare calculator <= 1.1.6 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Cab fare calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vehicle title setting in versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrar...

CVSS:
4.4
Affected:
up to 1.1.6
Fixed in:
1.1.7
Disclosed:
Sep 4, 2024

CVE-2022-3556 on NVD →

Cab fare calculator [cab-fare-calculator] < 1.0.4

unknown

[en] The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.

Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Apr 25, 2022

CVE-2022-1391 on NVD →

Cab fare calculator <= 1.0.3 - Unauthenticated Local File Inclusion

medium

The Cab fare calculator WordPress plugin through 1.0.3 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.

CVSS:
6.5
Affected:
up to 1.0.3
Fixed in:
1.0.4
Disclosed:
Apr 20, 2022

CVE-2022-1391 on NVD →

Cab fare calculator [cab-fare-calculator] <= 1.0.3

unknown

Unauthenticated Local File Inclusion (LFI) vulnerability was discovered by Hassan Khan Yusufzai (Splint3r7) in the WordPress Cab fare calculator plugin (versions <= 1.0.3).

Affected:
up to 1.0.3
Fixed in:
1.0.3
Disclosed:
Mar 30, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database