First published: Mon Nov 07 2022(Updated: )
The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fluent Forms | <4.3.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Contact Form Plugin WordPress vulnerability is CVE-2022-3463.
The severity level of CVE-2022-3463 is critical with a value of 9.8.
The affected software for CVE-2022-3463 is the Contact Form Plugin WordPress plugin before version 4.3.13.
CVE-2022-3463 is a vulnerability in the Contact Form Plugin WordPress plugin that allows CSV injection due to the lack of validation and escaping of fields when exporting form entries as CSV.
Yes, the fix for CVE-2022-3463 is to update the Contact Form Plugin WordPress plugin to version 4.3.13 or later.