CVE-2022-3463

CVE-2022-3463: FluentForm < 4.3.13 - CSV Injection

Vendor Unknown
Product Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms
Weakness CWE-1236
Published November 7, 2022
Last update May 1, 2025

CVSS base score

—

What the vulnerability does

01Description

The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection

Key dates

02Disclosure timeline

November 7, 2022 CVE published
May 1, 2025 Record updated