plugin

Assistant Vulnerabilities

9 known security issues reported for the Assistant WordPress plugin. Most recent disclosed Sep 5, 2025.

1 high 3 medium

Running Assistant on your site? Check whether your installed version is affected.

Scan your site free

Assistant &#8211; Every Day Productivity Apps [assistant] <= 1.5.2 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brent Jett Assistant allows Reflected XSS. This issue affects Assistant: from n/a through 1.5.2.

Affected:
up to 1.5.2
Fix:
No patched version reported
Disclosed:
Sep 5, 2025

CVE-2025-53307 on NVD →

WordPress Assistant <= 1.5.2 - Reflected Cross-Site Scripting

medium

The Assistant – Every Day Productivity Apps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...

CVSS:
6.1
Affected:
up to 1.5.2
Fixed in:
1.5.3
Disclosed:
Sep 3, 2025

CVE-2025-53307 on NVD →

Assistant &#8211; Every Day Productivity Apps [assistant] < 1.5.1.1 (closed)

unknown

[en] Deserialization of Untrusted Data vulnerability in Brent Jett Assistant allows Object Injection. This issue affects Assistant: from n/a through 1.5.1.

Affected:
up to 1.5.1.1
Fixed in:
1.5.1.1
Disclosed:
Mar 3, 2025

CVE-2025-26885 on NVD →

Assistant <= 1.5.1 - Authenticated (Editor+) PHP Object Injection

high

The Assistant plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with editor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable softwar...

CVSS:
7.2
Affected:
up to 1.5.1
Fixed in:
1.5.1.1
Disclosed:
Feb 22, 2025

CVE-2025-26885 on NVD →

Assistant &#8211; Every Day Productivity Apps [assistant] < 1.4.9.2 (closed)

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Fastline Media LLC Assistant – Every Day Productivity Apps.This issue affects Assistant – Every Day Productivity Apps: from n/a through 1.4.9.1.

Affected:
up to 1.4.9.2
Fixed in:
1.4.9.2
Disclosed:
Apr 29, 2024

CVE-2024-33538 on NVD →

Assistant – Every Day Productivity Apps <= 1.4.9.1 - Unauthenticated Sensitive Information Exposure

medium

The Assistant – Every Day Productivity Apps plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9.1 via publicly accessible files. This makes it possible for unauthenticated attackers to view potentially sensitive information stored in those files.

CVSS:
5.3
Affected:
up to 1.4.9.1
Fixed in:
1.4.9.2
Disclosed:
Apr 25, 2024

CVE-2024-33538 on NVD →

Assistant &#8211; Every Day Productivity Apps [assistant] < 1.4.4 (closed)

unknown

[en] The Assistant WordPress plugin before 1.4.4 does not validate a parameter before making a request to it via wp_remote_get(), which could allow users with a role as low as Editor to perform SSRF attacks

Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Oct 26, 2023

CVE-2023-5798 on NVD →

Assistant <= 1.4.3 - Authenticated (Editor+) Server Side Request Forgery

medium

The Assistant plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.4.3 via the /posts/(?P<id>\d+)/library/(?P<library_id>\d+) REST API endpoint. This can allow authenticated attackers, with editor-level capabilities and above, to make web requests to arbitrary locations...

CVSS:
5.5
Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Jul 27, 2023

CVE-2023-5798 on NVD →

Assistant &#8211; Every Day Productivity Apps [assistant] < 1.4.4 (closed)

unknown

The Assistant plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.4.3 via the /posts/(?P<id>\d+)/library/(?P<library_id>\d+) REST API endpoint. This can allow authenticated attackers, with editor-level capabilities and above, to make web requests to arbitrary locations...

Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Jul 27, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database