CVE-2020-11548

The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
References
Link Resource
https://www.exploit-db.com/exploits/48197 Third Party Advisory VDB Entry
https://wordpress.org/plugins/search-meter/#developers Product Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:search_meter_project:search_meter:*:*:*:*:*:wordpress:*:*

Information

Published : 2020-04-04 17:15

Updated : 2021-07-21 04:39


NVD link : CVE-2020-11548

Mitre link : CVE-2020-11548


JSON object : View

CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File

Advertisement

dedicated server usa

Products Affected

search_meter_project

  • search_meter