CVE-2020-11548

The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
References
Link Resource
https://www.exploit-db.com/exploits/48197 Third Party Advisory VDB Entry
https://wordpress.org/plugins/search-meter/#developers Product Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:search_meter_project:search_meter:*:*:*:*:*:wordpress:*:*

Information

Published : 2020-04-05 12:15

Updated : 2021-07-21 11:39


NVD link : CVE-2020-11548

Mitre link : CVE-2020-11548

Products Affected
No products.
CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File