CVE-2024-3214
The Relevanssi search plugin contained a CSV injection flaw affecting versions prior to 4.22.2 that could allow attackers to embed malicious formulas into exported CSV files, potentially leading to command execution or system compromise when the files are opened in spreadsheet applications. A security researcher identified and reported this vulnerability, which has been patched in version 4.22.2 and later. Users should upgrade their installation to the fixed version immediately to prevent exploitation.
Based on public CVE data (MITRE/NVD).