The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-04-04T23:48:14
Updated: 2024-08-04T11:35:13.335Z
Reserved: 2020-04-04T00:00:00
Link: CVE-2020-11548
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-04-05T00:15:11.940
Modified: 2024-11-21T04:58:07.750
Link: CVE-2020-11548
Redhat
No data.