CVE · Critical

CVE-2022-3463 — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 4.3.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3463 Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 4.3.13 Improper Neutralization of Formula Elements in a CSV File Critical 9.8 < 4.3.13 4.3.13 2022-10-17

CVE-2022-3463

The Contact Form Plugin by FluentForm contains a CSV injection vulnerability in versions up to 4.3.12 that enables attackers to inject malicious code into CSV exports. When users download and open these compromised CSV files on systems with susceptible configurations, the embedded code can execute on their local machines. This flaw was addressed in version 4.3.13.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.