The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
References
Link Resource
https://wordpress.org/plugins/search-meter/#developers Product Third Party Advisory
https://www.exploit-db.com/exploits/48197 Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-04-04T23:48:14

Updated: 2020-04-04T23:48:14

Reserved: 2020-04-04T00:00:00


Link: CVE-2020-11548

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-04-05T00:15:11.940

Modified: 2021-07-21T11:39:23.747


Link: CVE-2020-11548

JSON object: View

cve-icon Redhat Information

No data.

CWE