CVE-2022-40700

Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long Watch Studio WooSupply – Suppliers, Supply Orders and Stock Management, Squidesma Theme Minifier, Paul Clark Styles styles, Designmodo Inc. WordPress Page Builder – Qards, Philip M. Hofer (Frumph) PHPFreeChat, Arun Basil Lal Custom Login Admin Front-end CSS, Team Agence-Press CSS Adder By Agence-Press, Unihost Confirm Data, deano1987 AMP Toolbox amp-toolbox, Arun Basil Lal Admin CSS MU.This issue affects Montonio for WooCommerce: from n/a through 6.0.1; Wpopal Core Features: from n/a through 1.5.8; ArcStone: from n/a through 4.6.6; WooVirtualWallet – A virtual wallet for WooCommerce: from n/a through 2.2.1; WooVIP – Membership plugin for WordPress and WooCommerce: from n/a through 1.4.4; WooSupply – Suppliers, Supply Orders and Stock Management: from n/a through 1.2.2; Theme Minifier: from n/a through 2.0; Styles: from n/a through 1.2.3; WordPress Page Builder – Qards: from n/a through 1.0.5; PHPFreeChat: from n/a through 0.2.8; Custom Login Admin Front-end CSS: from n/a through 1.4.1; CSS Adder By Agence-Press: from n/a through 1.5.0; Confirm Data: from n/a through 1.0.7; AMP Toolbox: from n/a through 2.1.1; Admin CSS MU: from n/a through 2.6.
References
Link Resource
https://patchstack.com/database/vulnerability/admin-css-mu/wordpress-admin-css-mu-plugin-2-6-server-side-request-forgery-ssrf-vulnerability?_s_id=cve Third Party Advisory
https://patchstack.com/database/vulnerability/amp-toolbox/wordpress-amp-toolbox-plugin-2-1-1-server-side-request-forgery-ssrf?_s_id=cve Third Party Advisory
https://patchstack.com/database/vulnerability/confirm-data/wordpress-confirm-data-plugin-1-0-7-unauth-server-side-request-forgery-ssrf-vulnerability?_s_id=cve Third Party Advisory
https://patchstack.com/database/vulnerability/css-adder-by-agence-press/wordpress-css-adder-by-agene-press-plugin-1-5-0-server-side-request-forgery-ssrf?_s_id=cve Third Party Advisory
https://patchstack.com/database/vulnerability/custom-login-admin-front-end-css-with-multisite-support/wordpress-custom-login-admin-front-end-css-plugin-1-4-1-server-side-request-forgery-ssrf?_s_id=cve Third Party Advisory
https://patchstack.com/database/vulnerability/montonio-for-woocommerce/wordpress-montonio-for-woocommerce-plugin-6-0-1-server-side-request-forgery-ssrf?_s_id=cve Third Party Advisory
https://patchstack.com/database/vulnerability/phpfreechat/wordpress-phpfreechat-plugin-0-2-8-server-side-request-forgery-ssrf?_s_id=cve Third Party Advisory
https://patchstack.com/database/vulnerability/qards-free/wordpress-wordpress-page-builder-qards-plugin-1-0-5-server-side-request-forgery-ssrf?_s_id=cve Third Party Advisory
https://patchstack.com/database/vulnerability/styles/wordpress-styles-plugin-1-2-3-server-side-request-forgery-ssrf?_s_id=cve Third Party Advisory
https://patchstack.com/database/vulnerability/theme-minifier/wordpress-theme-minifier-plugin-2-0-server-side-request-forgery-ssrf?_s_id=cve Third Party Advisory
https://patchstack.com/database/vulnerability/woosupply/wordpress-woosupply-plugin-1-2-2-server-side-request-forgery-ssrf?_s_id=cve Third Party Advisory
https://patchstack.com/database/vulnerability/woovip/wordpress-woovip-plugin-1-4-4-server-side-request-forgery-ssrf?_s_id=cve Third Party Advisory
https://patchstack.com/database/vulnerability/woovirtualwallet/wordpress-woovirtualwallet-plugin-2-2-1-server-side-request-forgery-ssrf?_s_id=cve Third Party Advisory
https://patchstack.com/database/vulnerability/wp-amo/wordpress-amo-for-wp-plugin-4-6-6-server-side-request-forgery-ssrf?_s_id=cve Third Party Advisory
https://patchstack.com/database/vulnerability/wpopal-core-features/wordpress-wpopal-core-features-plugin-1-5-7-server-side-request-forgery-ssrf?_s_id=cve Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:millionclues:admin_css_mu:*:*:*:*:*:wordpress:*:*

Configuration 2 (hide)

cpe:2.3:a:deano:amp_toolbox:*:*:*:*:*:wordpress:*:*

Configuration 3 (hide)

cpe:2.3:a:unihost:confirm_data:*:*:*:*:*:wordpress:*:*

Configuration 4 (hide)

cpe:2.3:a:agence-press:css_adder:*:*:*:*:*:wordpress:*:*

Configuration 5 (hide)

cpe:2.3:a:millionclues:custom_login_admin_front-end_css:*:*:*:*:*:wordpress:*:*

Configuration 6 (hide)

cpe:2.3:a:montonio:montonio_for_woocommerce:*:*:*:*:*:wordpress:*:*

Configuration 7 (hide)

cpe:2.3:a:frumph:phpfreechat:*:*:*:*:*:wordpress:*:*

Configuration 8 (hide)

cpe:2.3:a:designmodo:qards:*:*:*:*:*:wordpress:*:*

Configuration 9 (hide)

cpe:2.3:a:paulclark:styles:*:*:*:*:*:wordpress:*:*

Configuration 10 (hide)

cpe:2.3:a:squidesma:theme_minifier:*:*:*:*:*:wordpress:*:*

Configuration 11 (hide)

OR cpe:2.3:a:longwatchstudio:woosupply:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:longwatchstudio:woovip:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:longwatchstudio:woovirtualwallet:*:*:*:*:*:wordpress:*:*

Configuration 12 (hide)

cpe:2.3:a:arcstone:amo_for_wp_-_membership_management:*:*:*:*:*:wordpress:*:*

Configuration 13 (hide)

cpe:2.3:a:wpopal:wpopal_core_features:*:*:*:*:*:wordpress:*:*

History

30 Jan 2024, 23:03

Type Values Removed Values Added
References () https://patchstack.com/database/vulnerability/admin-css-mu/wordpress-admin-css-mu-plugin-2-6-server-side-request-forgery-ssrf-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/admin-css-mu/wordpress-admin-css-mu-plugin-2-6-server-side-request-forgery-ssrf-vulnerability?_s_id=cve - Third Party Advisory
References () https://patchstack.com/database/vulnerability/amp-toolbox/wordpress-amp-toolbox-plugin-2-1-1-server-side-request-forgery-ssrf?_s_id=cve - () https://patchstack.com/database/vulnerability/amp-toolbox/wordpress-amp-toolbox-plugin-2-1-1-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory
References () https://patchstack.com/database/vulnerability/confirm-data/wordpress-confirm-data-plugin-1-0-7-unauth-server-side-request-forgery-ssrf-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/confirm-data/wordpress-confirm-data-plugin-1-0-7-unauth-server-side-request-forgery-ssrf-vulnerability?_s_id=cve - Third Party Advisory
References () https://patchstack.com/database/vulnerability/css-adder-by-agence-press/wordpress-css-adder-by-agene-press-plugin-1-5-0-server-side-request-forgery-ssrf?_s_id=cve - () https://patchstack.com/database/vulnerability/css-adder-by-agence-press/wordpress-css-adder-by-agene-press-plugin-1-5-0-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory
References () https://patchstack.com/database/vulnerability/custom-login-admin-front-end-css-with-multisite-support/wordpress-custom-login-admin-front-end-css-plugin-1-4-1-server-side-request-forgery-ssrf?_s_id=cve - () https://patchstack.com/database/vulnerability/custom-login-admin-front-end-css-with-multisite-support/wordpress-custom-login-admin-front-end-css-plugin-1-4-1-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory
References () https://patchstack.com/database/vulnerability/montonio-for-woocommerce/wordpress-montonio-for-woocommerce-plugin-6-0-1-server-side-request-forgery-ssrf?_s_id=cve - () https://patchstack.com/database/vulnerability/montonio-for-woocommerce/wordpress-montonio-for-woocommerce-plugin-6-0-1-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory
References () https://patchstack.com/database/vulnerability/phpfreechat/wordpress-phpfreechat-plugin-0-2-8-server-side-request-forgery-ssrf?_s_id=cve - () https://patchstack.com/database/vulnerability/phpfreechat/wordpress-phpfreechat-plugin-0-2-8-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory
References () https://patchstack.com/database/vulnerability/qards-free/wordpress-wordpress-page-builder-qards-plugin-1-0-5-server-side-request-forgery-ssrf?_s_id=cve - () https://patchstack.com/database/vulnerability/qards-free/wordpress-wordpress-page-builder-qards-plugin-1-0-5-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory
References () https://patchstack.com/database/vulnerability/styles/wordpress-styles-plugin-1-2-3-server-side-request-forgery-ssrf?_s_id=cve - () https://patchstack.com/database/vulnerability/styles/wordpress-styles-plugin-1-2-3-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory
References () https://patchstack.com/database/vulnerability/theme-minifier/wordpress-theme-minifier-plugin-2-0-server-side-request-forgery-ssrf?_s_id=cve - () https://patchstack.com/database/vulnerability/theme-minifier/wordpress-theme-minifier-plugin-2-0-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory
References () https://patchstack.com/database/vulnerability/woosupply/wordpress-woosupply-plugin-1-2-2-server-side-request-forgery-ssrf?_s_id=cve - () https://patchstack.com/database/vulnerability/woosupply/wordpress-woosupply-plugin-1-2-2-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory
References () https://patchstack.com/database/vulnerability/woovip/wordpress-woovip-plugin-1-4-4-server-side-request-forgery-ssrf?_s_id=cve - () https://patchstack.com/database/vulnerability/woovip/wordpress-woovip-plugin-1-4-4-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory
References () https://patchstack.com/database/vulnerability/woovirtualwallet/wordpress-woovirtualwallet-plugin-2-2-1-server-side-request-forgery-ssrf?_s_id=cve - () https://patchstack.com/database/vulnerability/woovirtualwallet/wordpress-woovirtualwallet-plugin-2-2-1-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory
References () https://patchstack.com/database/vulnerability/wp-amo/wordpress-amo-for-wp-plugin-4-6-6-server-side-request-forgery-ssrf?_s_id=cve - () https://patchstack.com/database/vulnerability/wp-amo/wordpress-amo-for-wp-plugin-4-6-6-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory
References () https://patchstack.com/database/vulnerability/wpopal-core-features/wordpress-wpopal-core-features-plugin-1-5-7-server-side-request-forgery-ssrf?_s_id=cve - () https://patchstack.com/database/vulnerability/wpopal-core-features/wordpress-wpopal-core-features-plugin-1-5-7-server-side-request-forgery-ssrf?_s_id=cve - Third Party Advisory
CVSS v2 : unknown
v3 : 8.2
v2 : unknown
v3 : 9.8
Summary
  • (es) Vulnerabilidad de Server-Side Request Forgery (SSRF) en Montonio Montonio para WooCommerce, Wpopal Funciones principales de Wpopal, AMO para WP – Gestión de membresía ArcStone wp-amo, Long Watch Studio WooVirtualWallet – Una billetera virtual para WooCommerce, Long Watch Studio WooVIP – Complemento de membresía para WordPress y WooCommerce, Long Watch Studio WooSupply: proveedores, pedidos de suministro y gestión de existencias, Squidesma Theme Minifier, estilos Paul Clark Styles, Designmodo Inc. Creador de páginas de WordPress: Qards, Philip M. Hofer (Frumph) PHPFreeChat, Arun Basil Lal Administrador de inicio de sesión personalizado CSS front-end, Team Agence-Press CSS Adder de Agence-Press, Unihost Confirm Data, deano1987 AMP Toolbox amp-toolbox, Arun Basil Lal Admin CSS MU. Este problema afecta a Montonio para WooCommerce: desde n/a hasta 6.0.1; Funciones principales de Wpopal: desde n/a hasta 1.5.8; ArcStone: desde n/a hasta 4.6.6; WooVirtualWallet: una billetera virtual para WooCommerce: desde n/a hasta 2.2.1; WooVIP: complemento de membresía para WordPress y WooCommerce: desde n/a hasta 1.4.4; WooSupply – Proveedores, pedidos de suministro y gestión de existencias: desde n/a hasta 1.2.2; Minificador de temas: desde n/a hasta 2.0; Estilos: desde n/a hasta 1.2.3; Creador de páginas de WordPress – Qards: desde n/a hasta 1.0.5; PHPFreeChat: desde n/a hasta 0.2.8; CSS de front-end de administrador de inicio de sesión personalizado: desde n/a hasta 1.4.1; Complemento CSS de Agence-Press: desde n/a hasta 1.5.0; Confirmar datos: desde n/a hasta 1.0.7; Caja de herramientas AMP: desde n/a hasta 2.1.1; Administrador CSS MU: desde n/a hasta 2.6.
First Time Montonio montonio For Woocommerce
Longwatchstudio woovirtualwallet
Agence-press
Wpopal
Millionclues custom Login Admin Front-end Css
Unihost confirm Data
Squidesma theme Minifier
Designmodo qards
Agence-press css Adder
Millionclues admin Css Mu
Designmodo
Frumph
Longwatchstudio woovip
Paulclark
Deano amp Toolbox
Wpopal wpopal Core Features
Deano
Longwatchstudio woosupply
Squidesma
Arcstone
Paulclark styles
Frumph phpfreechat
Montonio
Arcstone amo For Wp - Membership Management
Unihost
Millionclues
Longwatchstudio
CPE cpe:2.3:a:arcstone:amo_for_wp_-_membership_management:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:montonio:montonio_for_woocommerce:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:millionclues:custom_login_admin_front-end_css:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:squidesma:theme_minifier:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:longwatchstudio:woovirtualwallet:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:millionclues:admin_css_mu:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:unihost:confirm_data:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:paulclark:styles:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:longwatchstudio:woosupply:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:frumph:phpfreechat:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:longwatchstudio:woovip:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:deano:amp_toolbox:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:agence-press:css_adder:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:wpopal:wpopal_core_features:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:designmodo:qards:*:*:*:*:*:wordpress:*:*

19 Jan 2024, 15:56

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-19 15:15

Updated : 2024-01-30 23:03


NVD link : CVE-2022-40700

Mitre link : CVE-2022-40700

CVE.ORG link : CVE-2022-40700


JSON object : View

Products Affected

paulclark

  • styles

designmodo

  • qards

millionclues

  • admin_css_mu
  • custom_login_admin_front-end_css

agence-press

  • css_adder

montonio

  • montonio_for_woocommerce

longwatchstudio

  • woovirtualwallet
  • woovip
  • woosupply

wpopal

  • wpopal_core_features

arcstone

  • amo_for_wp_-_membership_management

squidesma

  • theme_minifier

unihost

  • confirm_data

frumph

  • phpfreechat

deano

  • amp_toolbox
CWE
CWE-918

Server-Side Request Forgery (SSRF)