Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long Watch Studio WooSupply – Suppliers, Supply Orders and Stock Management, Squidesma Theme Minifier, Paul Clark Styles styles, Designmodo Inc. WordPress Page Builder – Qards, Philip M. Hofer (Frumph) PHPFreeChat, Arun Basil Lal Custom Login Admin Front-end CSS, Team Agence-Press CSS Adder By Agence-Press, Unihost Confirm Data, deano1987 AMP Toolbox amp-toolbox, Arun Basil Lal Admin CSS MU.This issue affects Montonio for WooCommerce: from n/a through 6.0.1; Wpopal Core Features: from n/a through 1.5.8; ArcStone: from n/a through 4.6.6; WooVirtualWallet – A virtual wallet for WooCommerce: from n/a through 2.2.1; WooVIP – Membership plugin for WordPress and WooCommerce: from n/a through 1.4.4; WooSupply – Suppliers, Supply Orders and Stock Management: from n/a through 1.2.2; Theme Minifier: from n/a through 2.0; Styles: from n/a through 1.2.3; WordPress Page Builder – Qards: from n/a through 1.0.5; PHPFreeChat: from n/a through 0.2.8; Custom Login Admin Front-end CSS: from n/a through 1.4.1; CSS Adder By Agence-Press: from n/a through 1.5.0; Confirm Data: from n/a through 1.0.7; AMP Toolbox: from n/a through 2.1.1; Admin CSS MU: from n/a through 2.6.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
Configuration 8 (hide)
|
Configuration 9 (hide)
|
Configuration 10 (hide)
|
Configuration 11 (hide)
|
Configuration 12 (hide)
|
Configuration 13 (hide)
|
History
30 Jan 2024, 23:03
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://patchstack.com/database/vulnerability/admin-css-mu/wordpress-admin-css-mu-plugin-2-6-server-side-request-forgery-ssrf-vulnerability?_s_id=cve - Third Party Advisory | |
| References | () https://patchstack.com/database/vulnerability/amp-toolbox/wordpress-amp-toolbox-plugin-2-1-1-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory | |
| References | () https://patchstack.com/database/vulnerability/confirm-data/wordpress-confirm-data-plugin-1-0-7-unauth-server-side-request-forgery-ssrf-vulnerability?_s_id=cve - Third Party Advisory | |
| References | () https://patchstack.com/database/vulnerability/css-adder-by-agence-press/wordpress-css-adder-by-agene-press-plugin-1-5-0-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory | |
| References | () https://patchstack.com/database/vulnerability/custom-login-admin-front-end-css-with-multisite-support/wordpress-custom-login-admin-front-end-css-plugin-1-4-1-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory | |
| References | () https://patchstack.com/database/vulnerability/montonio-for-woocommerce/wordpress-montonio-for-woocommerce-plugin-6-0-1-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory | |
| References | () https://patchstack.com/database/vulnerability/phpfreechat/wordpress-phpfreechat-plugin-0-2-8-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory | |
| References | () https://patchstack.com/database/vulnerability/qards-free/wordpress-wordpress-page-builder-qards-plugin-1-0-5-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory | |
| References | () https://patchstack.com/database/vulnerability/styles/wordpress-styles-plugin-1-2-3-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory | |
| References | () https://patchstack.com/database/vulnerability/theme-minifier/wordpress-theme-minifier-plugin-2-0-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory | |
| References | () https://patchstack.com/database/vulnerability/woosupply/wordpress-woosupply-plugin-1-2-2-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory | |
| References | () https://patchstack.com/database/vulnerability/woovip/wordpress-woovip-plugin-1-4-4-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory | |
| References | () https://patchstack.com/database/vulnerability/woovirtualwallet/wordpress-woovirtualwallet-plugin-2-2-1-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory | |
| References | () https://patchstack.com/database/vulnerability/wp-amo/wordpress-amo-for-wp-plugin-4-6-6-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory | |
| References | () https://patchstack.com/database/vulnerability/wpopal-core-features/wordpress-wpopal-core-features-plugin-1-5-7-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| Summary |
|
|
| First Time |
Montonio montonio For Woocommerce
Longwatchstudio woovirtualwallet Agence-press Wpopal Millionclues custom Login Admin Front-end Css Unihost confirm Data Squidesma theme Minifier Designmodo qards Agence-press css Adder Millionclues admin Css Mu Designmodo Frumph Longwatchstudio woovip Paulclark Deano amp Toolbox Wpopal wpopal Core Features Deano Longwatchstudio woosupply Squidesma Arcstone Paulclark styles Frumph phpfreechat Montonio Arcstone amo For Wp - Membership Management Unihost Millionclues Longwatchstudio |
|
| CPE | cpe:2.3:a:arcstone:amo_for_wp_-_membership_management:*:*:*:*:*:wordpress:*:* cpe:2.3:a:montonio:montonio_for_woocommerce:*:*:*:*:*:wordpress:*:* cpe:2.3:a:millionclues:custom_login_admin_front-end_css:*:*:*:*:*:wordpress:*:* cpe:2.3:a:squidesma:theme_minifier:*:*:*:*:*:wordpress:*:* cpe:2.3:a:longwatchstudio:woovirtualwallet:*:*:*:*:*:wordpress:*:* cpe:2.3:a:millionclues:admin_css_mu:*:*:*:*:*:wordpress:*:* cpe:2.3:a:unihost:confirm_data:*:*:*:*:*:wordpress:*:* cpe:2.3:a:paulclark:styles:*:*:*:*:*:wordpress:*:* cpe:2.3:a:longwatchstudio:woosupply:*:*:*:*:*:wordpress:*:* cpe:2.3:a:frumph:phpfreechat:*:*:*:*:*:wordpress:*:* cpe:2.3:a:longwatchstudio:woovip:*:*:*:*:*:wordpress:*:* cpe:2.3:a:deano:amp_toolbox:*:*:*:*:*:wordpress:*:* cpe:2.3:a:agence-press:css_adder:*:*:*:*:*:wordpress:*:* cpe:2.3:a:wpopal:wpopal_core_features:*:*:*:*:*:wordpress:*:* cpe:2.3:a:designmodo:qards:*:*:*:*:*:wordpress:*:* |
19 Jan 2024, 15:56
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-01-19 15:15
Updated : 2024-01-30 23:03
NVD link : CVE-2022-40700
Mitre link : CVE-2022-40700
CVE.ORG link : CVE-2022-40700
JSON object : View
Products Affected
paulclark
- styles
designmodo
- qards
millionclues
- admin_css_mu
- custom_login_admin_front-end_css
agence-press
- css_adder
montonio
- montonio_for_woocommerce
longwatchstudio
- woovirtualwallet
- woovip
- woosupply
wpopal
- wpopal_core_features
arcstone
- amo_for_wp_-_membership_management
squidesma
- theme_minifier
unihost
- confirm_data
frumph
- phpfreechat
deano
- amp_toolbox
CWE
CWE-918
Server-Side Request Forgery (SSRF)
