← Back

Assistant

assistant

Vendor: Fastlinemedia • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fastlinemedia
1Assistant
Apr 23, 2025
Oct 26, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Assistant WordPress plugin before 1.4.4 does not validate a parameter before making a request to it via wp_remote_get(), which could allow users with a role as low as Editor to perform SSRF attacks