PoC Index

CVE-2020-11548

CRITICAL 9.8EPSS 5.2%

The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
5.17% chance of exploitation in the next 30 days, 92th percentile
Published
2020-04-04
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related