CVE Published: 07/11/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: WPScan |
Vendor: Unknown |
Product: Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms Status : PUBLISHED
CVE-2022-3463 Description
The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection