Executive Summary

Informations
Name CVE-2022-40700 First vendor Publication 2024-01-19
Vendor Cve Last vendor Modification 2024-01-30

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Overall CVSS Score 9.8
Base Score 9.8 Environmental Score 9.8
impact SubScore 5.9 Temporal Score 9.8
Exploitabality Sub Score 3.9
 
Attack Vector Network Attack Complexity Low
Privileges Required None User Interaction None
Scope Unchanged Confidentiality Impact High
Integrity Impact High Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long Watch Studio WooSupply – Suppliers, Supply Orders and Stock Management, Squidesma Theme Minifier, Paul Clark Styles styles, Designmodo Inc. WordPress Page Builder – Qards, Philip M. Hofer (Frumph) PHPFreeChat, Arun Basil Lal Custom Login Admin Front-end CSS, Team Agence-Press CSS Adder By Agence-Press, Unihost Confirm Data, deano1987 AMP Toolbox amp-toolbox, Arun Basil Lal Admin CSS MU.This issue affects Montonio for WooCommerce: from n/a through 6.0.1; Wpopal Core Features: from n/a through 1.5.8; ArcStone: from n/a through 4.6.6; WooVirtualWallet – A virtual wallet for WooCommerce: from n/a through 2.2.1; WooVIP – Membership plugin for WordPress and WooCommerce: from n/a through 1.4.4; WooSupply – Suppliers, Supply Orders and Stock Management: from n/a through 1.2.2; Theme Minifier: from n/a through 2.0; Styles: from n/a through 1.2.3; WordPress Page Builder – Qards: from n/a through 1.0.5; PHPFreeChat: from n/a through 0.2.8; Custom Login Admin Front-end CSS: from n/a through 1.4.1; CSS Adder By Agence-Press: from n/a through 1.5.0; Confirm Data: from n/a through 1.0.7; AMP Toolbox: from n/a through 2.1.1; Admin CSS MU: from n/a through 2.6.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40700

Sources (Detail)

https://patchstack.com/database/vulnerability/admin-css-mu/wordpress-admin-cs...
https://patchstack.com/database/vulnerability/amp-toolbox/wordpress-amp-toolb...
https://patchstack.com/database/vulnerability/confirm-data/wordpress-confirm-...
https://patchstack.com/database/vulnerability/css-adder-by-agence-press/wordp...
https://patchstack.com/database/vulnerability/custom-login-admin-front-end-cs...
https://patchstack.com/database/vulnerability/montonio-for-woocommerce/wordpr...
https://patchstack.com/database/vulnerability/phpfreechat/wordpress-phpfreech...
https://patchstack.com/database/vulnerability/qards-free/wordpress-wordpress-...
https://patchstack.com/database/vulnerability/styles/wordpress-styles-plugin-...
https://patchstack.com/database/vulnerability/theme-minifier/wordpress-theme-...
https://patchstack.com/database/vulnerability/woosupply/wordpress-woosupply-p...
https://patchstack.com/database/vulnerability/woovip/wordpress-woovip-plugin-...
https://patchstack.com/database/vulnerability/woovirtualwallet/wordpress-woov...
https://patchstack.com/database/vulnerability/wp-amo/wordpress-amo-for-wp-plu...
https://patchstack.com/database/vulnerability/wpopal-core-features/wordpress-...
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2024-01-31 05:27:32
  • Multiple Updates
2024-01-19 21:27:25
  • First insertion