CVE-2023-5798: Assistant < 1.4.4 - Editor+ SSRF
Published Oct 26, 2023
·Updated
The Assistant WordPress plugin before 1.4.4 does not validate a parameter before making a request to it via wpremoteget(), which could allow users with a role as low as Editor to perform SSRF attacks
Affected Software
1 affected component
Fastlinemedia Assistant Wordpress<1.4.4
Event History
Oct 26, 2023
CVE Published
via MITRE·09:08 AM
Data Sourced
via MITRE·09:08 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-5798.
2
What is the severity of CVE-2023-5798?
The severity of CVE-2023-5798 is high (8.8).
3
What is the affected software?
The affected software is Fastlinemedia Assistant WordPress plugin version up to but excluding 1.4.4.
4
What is the description of CVE-2023-5798?
CVE-2023-5798 is a vulnerability in the Assistant WordPress plugin before 1.4.4 that allows users with a role as low as Editor to perform server-side request forgery (SSRF) attacks.
5
How can the vulnerability CVE-2023-5798 be exploited?
The vulnerability CVE-2023-5798 can be exploited by an Editor-level user sending unauthorized server requests through the plugin.