Vulnerabilities > CVE-2023-5798 - Unspecified vulnerability in Fastlinemedia Assistant

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
fastlinemedia

Summary

The Assistant WordPress plugin before 1.4.4 does not validate a parameter before making a request to it via wp_remote_get(), which could allow users with a role as low as Editor to perform SSRF attacks

Vulnerable Configurations

Part Description Count
Application
Fastlinemedia
52