CVE-2024-3214: Relevanssi – A Better Search <= 4.22.1 - Unauthenticated Second Order CSV Injection
The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3214?
CVE-2024-3214 is considered a high severity vulnerability due to the potential for code execution through CSV Injection.
How do I fix CVE-2024-3214?
To fix CVE-2024-3214, update the Relevanssi – A Better Search plugin to version 4.22.2 or later.
Who is affected by CVE-2024-3214?
All users of Relevanssi – A Better Search plugin for WordPress up to version 4.22.1 are affected by CVE-2024-3214.
Can CVE-2024-3214 be exploited by authenticated users?
No, CVE-2024-3214 can be exploited by unauthenticated attackers, making it particularly dangerous.
What types of attacks can result from CVE-2024-3214?
CVE-2024-3214 may allow attackers to execute arbitrary code when users download compromised CSV files.