CVE-2022-40700

EUVD-2022-43971
Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long Watch Studio WooSupply – Suppliers, Supply Orders and Stock Management, Squidesma Theme Minifier, Paul Clark Styles styles, Designmodo Inc. WordPress Page Builder – Qards, Philip M. Hofer (Frumph) PHPFreeChat, Arun Basil Lal Custom Login Admin Front-end CSS, Team Agence-Press CSS Adder By Agence-Press, Unihost Confirm Data, deano1987 AMP Toolbox amp-toolbox, Arun Basil Lal Admin CSS MU.This issue affects Montonio for WooCommerce: from n/a through 6.0.1; Wpopal Core Features: from n/a through 1.5.8; ArcStone: from n/a through 4.6.6; WooVirtualWallet – A virtual wallet for WooCommerce: from n/a through 2.2.1; WooVIP – Membership plugin for WordPress and WooCommerce: from n/a through 1.4.4; WooSupply – Suppliers, Supply Orders and Stock Management: from n/a through 1.2.2; Theme Minifier: from n/a through 2.0; Styles: from n/a through 1.2.3; WordPress Page Builder – Qards: from n/a through 1.0.5; PHPFreeChat: from n/a through 0.2.8; Custom Login Admin Front-end CSS: from n/a through 1.4.1; CSS Adder By Agence-Press: from n/a through 1.5.0; Confirm Data: from n/a through 1.0.7; AMP Toolbox: from n/a through 2.1.1; Admin CSS MU: from n/a through 2.6.

SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
PatchstackCNA
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
Affected Products (NVD)
VendorProductVersion
millioncluesadmin_css_mu
𝑥
≤ 2.6
deanoamp_toolbox
𝑥
≤ 2.1.1
unihostconfirm_data
𝑥
≤ 1.0.7
agence-presscss_adder
𝑥
≤ 1.5.0
millioncluescustom_login_admin_front-end_css
𝑥
≤ 1.4.1
montoniomontonio_for_woocommerce
𝑥
≤ 6.0.1
frumphphpfreechat
𝑥
≤ 0.2.8
designmodoqards
𝑥
≤ 1.0.5
paulclarkstyles
𝑥
≤ 1.2.3
squidesmatheme_minifier
𝑥
≤ 2.0
longwatchstudiowoosupply
𝑥
≤ 1.2.2
longwatchstudiowoovip
𝑥
≤ 1.4.4
longwatchstudiowoovirtualwallet
𝑥
≤ 2.2.1
arcstoneamo_for_wp_-_membership_management
𝑥
≤ 4.6.6
wpopalwpopal_core_features
𝑥
≤ 1.5.8
𝑥
= Vulnerable software versions
References