CVE-2022-40700

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
19/01/2024
Last modified:
30/01/2024

Description

Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long Watch Studio WooSupply – Suppliers, Supply Orders and Stock Management, Squidesma Theme Minifier, Paul Clark Styles styles, Designmodo Inc. WordPress Page Builder – Qards, Philip M. Hofer (Frumph) PHPFreeChat, Arun Basil Lal Custom Login Admin Front-end CSS, Team Agence-Press CSS Adder By Agence-Press, Unihost Confirm Data, deano1987 AMP Toolbox amp-toolbox, Arun Basil Lal Admin CSS MU.This issue affects Montonio for WooCommerce: from n/a through 6.0.1; Wpopal Core Features: from n/a through 1.5.8; ArcStone: from n/a through 4.6.6; WooVirtualWallet – A virtual wallet for WooCommerce: from n/a through 2.2.1; WooVIP – Membership plugin for WordPress and WooCommerce: from n/a through 1.4.4; WooSupply – Suppliers, Supply Orders and Stock Management: from n/a through 1.2.2; Theme Minifier: from n/a through 2.0; Styles: from n/a through 1.2.3; WordPress Page Builder – Qards: from n/a through 1.0.5; PHPFreeChat: from n/a through 0.2.8; Custom Login Admin Front-end CSS: from n/a through 1.4.1; CSS Adder By Agence-Press: from n/a through 1.5.0; Confirm Data: from n/a through 1.0.7; AMP Toolbox: from n/a through 2.1.1; Admin CSS MU: from n/a through 2.6.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:millionclues:admin_css_mu:*:*:*:*:*:wordpress:*:* 2.6 (including)
cpe:2.3:a:deano:amp_toolbox:*:*:*:*:*:wordpress:*:* 2.1.1 (including)
cpe:2.3:a:unihost:confirm_data:*:*:*:*:*:wordpress:*:* 1.0.7 (including)
cpe:2.3:a:agence-press:css_adder:*:*:*:*:*:wordpress:*:* 1.5.0 (including)
cpe:2.3:a:millionclues:custom_login_admin_front-end_css:*:*:*:*:*:wordpress:*:* 1.4.1 (including)
cpe:2.3:a:montonio:montonio_for_woocommerce:*:*:*:*:*:wordpress:*:* 6.0.1 (including)
cpe:2.3:a:frumph:phpfreechat:*:*:*:*:*:wordpress:*:* 0.2.8 (including)
cpe:2.3:a:designmodo:qards:*:*:*:*:*:wordpress:*:* 1.0.5 (including)
cpe:2.3:a:paulclark:styles:*:*:*:*:*:wordpress:*:* 1.2.3 (including)
cpe:2.3:a:squidesma:theme_minifier:*:*:*:*:*:wordpress:*:* 2.0 (including)
cpe:2.3:a:longwatchstudio:woosupply:*:*:*:*:*:wordpress:*:* 1.2.2 (including)
cpe:2.3:a:longwatchstudio:woovip:*:*:*:*:*:wordpress:*:* 1.4.4 (including)
cpe:2.3:a:longwatchstudio:woovirtualwallet:*:*:*:*:*:wordpress:*:* 2.2.1 (including)
cpe:2.3:a:arcstone:amo_for_wp_-_membership_management:*:*:*:*:*:wordpress:*:* 4.6.6 (including)
cpe:2.3:a:wpopal:wpopal_core_features:*:*:*:*:*:wordpress:*:* 1.5.8 (including)


References to Advisories, Solutions, and Tools