CVE-2020-11548

The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
References
Link Resource
https://wordpress.org/plugins/search-meter/#developers Product Third Party Advisory
https://www.exploit-db.com/exploits/48197 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:search_meter_project:search_meter:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2020-04-05 00:15

Updated : 2024-02-04 21:00


NVD link : CVE-2020-11548

Mitre link : CVE-2020-11548

CVE.ORG link : CVE-2020-11548


JSON object : View

Products Affected

search_meter_project

  • search_meter
CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File