Rewterz
Rewterz Threat Advisory – CVE-2022-3418 – WordPress Import any XML or CSV File Vulnerability
November 14, 2022
Rewterz
Rewterz Threat Alert – Amadey Botnet – Active IOCs
November 14, 2022

Rewterz Threat Advisory – CVE-2022-3463 – WordPress FluentForm Plugin Vulnerability

Severity

High

Analysis Summary

CVE-2022-3463

FluentForm plugin for WordPress could allow a remote attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. An attacker could exploit this vulnerability to execute arbitrary code on the system.

Impact

Code Execution

Indicators Of Compromise

CVE

  • CVE-2022-3463

Affected Vendors

WordPress

Affected Products

  • FluentForm plugin for WordPress 4.3.11
  • FluentForm plugin for WordPress 4.3.12

Remediation

Upgrade to the latest version of FluentForm plugin for WordPress, available from the WordPress Plugin Directory

WordPress Plugin Directory