CVE-2022-45350 LOW

CVE-2022-45350: WordPress Simple History Plugin <= 3.3.1 is vulnerable to CSV Injection

Vendor Pär Thernström
Product Simple History – user activity log, audit tool
Weakness CWE-1236
Published November 7, 2023
Last update April 28, 2026

CVSS base score

3.0/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N

What the vulnerability does

01Description

Improper Neutralization of Formula Elements in a CSV File vulnerability in Pär Thernström Simple History – user activity log, audit tool.This issue affects Simple History – user activity log, audit tool: from n/a through 3.3.1.

Explanation of Vulnerability in Simple Terms

02Summary

Simple History versions up to 3.3.1 contain an integrity vulnerability allowing authenticated users with low privileges to modify site content through a cross-site request forgery (CSRF) attack. The attacker must trick a logged-in administrator into visiting a malicious page. No confidentiality or availability impact occurs. Update to a version newer than 3.3.1.

What an attacker can do

03Attacker Capabilities

Modify site content or settings if a logged-in admin visits an attacker-controlled page.

Potential impact on your site

04Site Impact

An attacker with low-privilege access can alter site data if they trick an admin into visiting a crafted page.

Conditions required to exploit

05Prerequisites

Attacker needs a low-privilege account; victim (admin) must click a malicious link or visit attacker's page.

Key dates

06Disclosure timeline

November 7, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE