CVE-2022-40700

Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP  Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet  A virtual wallet for WooCommerce, Long Watch Studio WooVIP  Membership plugin for WordPress and WooCommerce, Long Watch Studio WooSupply  Suppliers, Supply Orders and Stock Management, Squidesma Theme Minifier, Paul Clark Styles styles, Designmodo Inc. WordPress Page Builder  Qards, Philip M. Hofer (Frumph) PHPFreeChat, Arun Basil Lal Custom Login Admin Front-end CSS, Team Agence-Press CSS Adder By Agence-Press, Unihost Confirm Data, deano1987 AMP Toolbox amp-toolbox, Arun Basil Lal Admin CSS MU.This issue affects Montonio for WooCommerce: from n/a through 6.0.1; Wpopal Core Features: from n/a through 1.5.8; ArcStone: from n/a through 4.6.6; WooVirtualWallet  A virtual wallet for WooCommerce: from n/a through 2.2.1; WooVIP  Membership plugin for WordPress and WooCommerce: from n/a through 1.4.4; WooSupply  Suppliers, Supply Orders and Stock Management: from n/a through 1.2.2; Theme Minifier: from n/a through 2.0; Styles: from n/a through 1.2.3; WordPress Page Builder  Qards: from n/a through 1.0.5; PHPFreeChat: from n/a through 0.2.8; Custom Login Admin Front-end CSS: from n/a through 1.4.1; CSS Adder By Agence-Press: from n/a through 1.5.0; Confirm Data: from n/a through 1.0.7; AMP Toolbox: from n/a through 2.1.1; Admin CSS MU: from n/a through 2.6.

SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
PatchstackCNA
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
VendorProductVersion
millioncluesadmin_css_mu
𝑥
≤ 2.6
deanoamp_toolbox
𝑥
≤ 2.1.1
unihostconfirm_data
𝑥
≤ 1.0.7
agence-presscss_adder
𝑥
≤ 1.5.0
millioncluescustom_login_admin_front-end_css
𝑥
≤ 1.4.1
montoniomontonio_for_woocommerce
𝑥
≤ 6.0.1
frumphphpfreechat
𝑥
≤ 0.2.8
designmodoqards
𝑥
≤ 1.0.5
paulclarkstyles
𝑥
≤ 1.2.3
squidesmatheme_minifier
𝑥
≤ 2.0
longwatchstudiowoosupply
𝑥
≤ 1.2.2
longwatchstudiowoovip
𝑥
≤ 1.4.4
longwatchstudiowoovirtualwallet
𝑥
≤ 2.2.1
arcstoneamo_for_wp_-_membership_management
𝑥
≤ 4.6.6
wpopalwpopal_core_features
𝑥
≤ 1.5.8
𝑥
= Vulnerable software versions
References