CVE · Critical

CVE-2024-3214 — Relevanssi – A Better Search [relevanssi] < 4.22.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3214 Relevanssi – A Better Search [relevanssi] < 4.22.2 Improper Neutralization of Formula Elements in a CSV File Critical 9.8 < 4.22.2 4.22.2 2024-04-04

CVE-2024-3214

The Relevanssi search plugin contained a CSV injection flaw affecting versions prior to 4.22.2 that could allow attackers to embed malicious formulas into exported CSV files, potentially leading to command execution or system compromise when the files are opened in spreadsheet applications. A security researcher identified and reported this vulnerability, which has been patched in version 4.22.2 and later. Users should upgrade their installation to the fixed version immediately to prevent exploitation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.