CVE-2020-11548: Search Meter Project Search Meter
Critical severity, CVSS 9.8. EPSS: 5.2% chance of exploitation in the next 30 days.
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
Affected products
- Search Meter Project Search Meter: up to and including 2.13.2
Published 2020-04-05. Last modified 2026-06-17.