Vulnerability Description
The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fluentforms | Contact Form | < 4.3.13 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/e2a59481-db45-4b8e-b17a-447303469364ExploitThird Party Advisory
- https://wpscan.com/vulnerability/e2a59481-db45-4b8e-b17a-447303469364ExploitThird Party Advisory
FAQ
What is CVE-2022-3463?
CVE-2022-3463 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection
How severe is CVE-2022-3463?
CVE-2022-3463 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-3463?
Check the references section above for vendor advisories and patch information. Affected products include: Fluentforms Contact Form.