CVE-2022-3463: FluentForm < 4.3.13 - CSV Injection
Published Nov 7, 2022
·Updated
The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection
Affected Software
1 affected component
FluentForms Contact Form Wordpress<4.3.13
Event History
Nov 7, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Contact Form Plugin WordPress vulnerability?
The vulnerability ID for the Contact Form Plugin WordPress vulnerability is CVE-2022-3463.
2
What is the severity level of CVE-2022-3463?
The severity level of CVE-2022-3463 is critical with a value of 9.8.
3
What is the affected software for CVE-2022-3463?
The affected software for CVE-2022-3463 is the Contact Form Plugin WordPress plugin before version 4.3.13.
4
What is the description of CVE-2022-3463?
CVE-2022-3463 is a vulnerability in the Contact Form Plugin WordPress plugin that allows CSV injection due to the lack of validation and escaping of fields when exporting form entries as CSV.
5
Is there a fix available for CVE-2022-3463?
Yes, the fix for CVE-2022-3463 is to update the Contact Form Plugin WordPress plugin to version 4.3.13 or later.