### [CVE-2023-5798](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5798) ![](https://img.shields.io/static/v1?label=Product&message=Assistant&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=0%3C%201.4.4%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-918%20Server-Side%20Request%20Forgery%20(SSRF)&color=brighgreen) ### Description The Assistant WordPress plugin before 1.4.4 does not validate a parameter before making a request to it via wp_remote_get(), which could allow users with a role as low as Editor to perform SSRF attacks ### POC #### Reference - https://wpscan.com/vulnerability/bbb4c98c-4dd7-421e-9666-98f15acde761 #### Github No PoCs found on GitHub currently.