HIGH · 8.2

CVE-2022-40700

Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWall...

Vulnerability Description

Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long Watch Studio WooSupply – Suppliers, Supply Orders and Stock Management, Squidesma Theme Minifier, Paul Clark Styles styles, Designmodo Inc. WordPress Page Builder – Qards, Philip M. Hofer (Frumph) PHPFreeChat, Arun Basil Lal Custom Login Admin Front-end CSS, Team Agence-Press CSS Adder By Agence-Press, Unihost Confirm Data, deano1987 AMP Toolbox amp-toolbox, Arun Basil Lal Admin CSS MU.This issue affects Montonio for WooCommerce: from n/a through 6.0.1; Wpopal Core Features: from n/a through 1.5.8; ArcStone: from n/a through 4.6.6; WooVirtualWallet – A virtual wallet for WooCommerce: from n/a through 2.2.1; WooVIP – Membership plugin for WordPress and WooCommerce: from n/a through 1.4.4; WooSupply – Suppliers, Supply Orders and Stock Management: from n/a through 1.2.2; Theme Minifier: from n/a through 2.0; Styles: from n/a through 1.2.3; WordPress Page Builder – Qards: from n/a through 1.0.5; PHPFreeChat: from n/a through 0.2.8; Custom Login Admin Front-end CSS: from n/a through 1.4.1; CSS Adder By Agence-Press: from n/a through 1.5.0; Confirm Data: from n/a through 1.0.7; AMP Toolbox: from n/a through 2.1.1; Admin CSS MU: from n/a through 2.6.

CVSS Score

8.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
MillioncluesAdmin Css Mu<= 2.6
DeanoAmp Toolbox<= 2.1.1
UnihostConfirm Data<= 1.0.7
Agence-PressCss Adder<= 1.5.0
MillioncluesCustom Login Admin Front-End Css<= 1.4.1
MontonioMontonio For Woocommerce<= 6.0.1
FrumphPhpfreechat<= 0.2.8
DesignmodoQards<= 1.0.5
PaulclarkStyles<= 1.2.3
SquidesmaTheme Minifier<= 2.0
LongwatchstudioWoosupply<= 1.2.2
LongwatchstudioWoovip<= 1.4.4
LongwatchstudioWoovirtualwallet<= 2.2.1
ArcstoneAmo For Wp - Membership Management<= 4.6.6
WpopalWpopal Core Features<= 1.5.8

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-40700?

CVE-2022-40700 is a vulnerability with a CVSS score of 8.2 (HIGH). Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWall...

How severe is CVE-2022-40700?

CVE-2022-40700 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-40700?

Check the references section above for vendor advisories and patch information. Affected products include: Millionclues Admin Css Mu, Deano Amp Toolbox, Unihost Confirm Data, Agence-Press Css Adder, Millionclues Custom Login Admin Front-End Css.