CVE-2022-40700

critical
Published 2024-01-19 · Modified 2026-04-28
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
9.8

Description

Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long Watch Studio WooSupply – Suppliers, Supply Orders and Stock Management, Squidesma Theme Minifier, Paul Clark Styles styles, Designmodo Inc. WordPress Page Builder – Qards, Philip M. Hofer (Frumph) PHPFreeChat, Arun Basil Lal Custom Login Admin Front-end CSS, Team Agence-Press CSS Adder By Agence-Press, Unihost Confirm Data, deano1987 AMP Toolbox amp-toolbox, Arun Basil Lal Admin CSS MU.This issue affects Montonio for WooCommerce: from n/a through 6.0.1; Wpopal Core Features: from n/a through 1.5.8; ArcStone: from n/a through 4.6.6; WooVirtualWallet – A virtual wallet for WooCommerce: from n/a through 2.2.1; WooVIP – Membership plugin for WordPress and WooCommerce: from n/a through 1.4.4; WooSupply – Suppliers, Supply Orders and Stock Management: from n/a through 1.2.2; Theme Minifier: from n/a through 2.0; Styles: from n/a through 1.2.3; WordPress Page Builder – Qards: from n/a through 1.0.5; PHPFreeChat: from n/a through 0.2.8; Custom Login Admin Front-end CSS: from n/a through 1.4.1; CSS Adder By Agence-Press: from n/a through 1.5.0; Confirm Data: from n/a through 1.0.7; AMP Toolbox: from n/a through 2.1.1; Admin CSS MU: from n/a through 2.6.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
millioncluesadmin_css_mu{"endIncluding":"2.6"}
deanoamp_toolbox{"endIncluding":"2.1.1"}
unihostconfirm_data{"endIncluding":"1.0.7"}
agence-presscss_adder{"endIncluding":"1.5.0"}
millioncluescustom_login_admin_front-end_css{"endIncluding":"1.4.1"}
montoniomontonio_for_woocommerce{"endIncluding":"6.0.1"}
frumphphpfreechat{"endIncluding":"0.2.8"}
designmodoqards{"endIncluding":"1.0.5"}
paulclarkstyles{"endIncluding":"1.2.3"}
squidesmatheme_minifier{"endIncluding":"2.0"}
longwatchstudiowoosupply{"endIncluding":"1.2.2"}
longwatchstudiowoovip{"endIncluding":"1.4.4"}
longwatchstudiowoovirtualwallet{"endIncluding":"2.2.1"}
arcstoneamo_for_wp_-_membership_management{"endIncluding":"4.6.6"}
wpopalwpopal_core_features{"endIncluding":"1.5.8"}

References

CWEs

CWE-918

Verify integrity in audit chain (admin only). AS-IS.