CVE Database /
CVE-2022-3463
CVE · Critical
CVE-2022-3463 — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 4.3.13
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-3463
|
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 4.3.13 |
Improper Neutralization of Formula Elements in a CSV File |
Critical
9.8
|
< 4.3.13
|
4.3.13 |
2022-10-17 |
—
|
CVE-2022-3463
The Contact Form Plugin by FluentForm contains a CSV injection vulnerability in versions up to 4.3.12 that enables attackers to inject malicious code into CSV exports. When users download and open these compromised CSV files on systems with susceptible configurations, the embedded code can execute on their local machines. This flaw was addressed in version 4.3.13.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings