Severity
High
Analysis Summary
CVE-2022-3463
FluentForm plugin for WordPress could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. An attacker could exploit this vulnerability to execute arbitrary code on the system.
Impact
Code Execution
Indicators Of Compromise
CVE
- CVE-2022-3463
Affected Vendors
WordPress
Affected Products
- FluentForm plugin for WordPress 4.3.11
- FluentForm plugin for WordPress 4.3.12
Remediation
Upgrade to the latest version of FluentForm plugin for WordPress, available from the WordPress Plugin Directory