Fiche vulnérabilité
CVE-2022-40700 : faille critique millionclues admin css mu (CVSS 9.8)
Description
Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long Watch Studio WooSupply – Suppliers, Supply Orders and Stock Management, Squidesma Theme Minifier, Paul Clark Styles styles, Designmodo Inc. WordPress Page Builder – Qards, Philip M. Hofer (Frumph) PHPFreeChat, Arun Basil Lal Custom Login Admin Front-end CSS, Team Agence-Press CSS Adder By Agence-Press, Unihost Confirm Data, deano1987 AMP Toolbox amp-toolbox, Arun Basil Lal Admin CSS MU.This issue affects Montonio for WooCommerce: from n/a through 6.0.1; Wpopal Core Features: from n/a through 1.5.8; ArcStone: from n/a through 4.6.6; WooVirtualWallet – A virtual wallet for WooCommerce: from n/a through 2.2.1; WooVIP – Membership plugin for WordPress and WooCommerce: from n/a through 1.4.4; WooSupply – Suppliers, Supply Orders and Stock Management: from n/a through 1.2.2; Theme Minifier: from n/a through 2.0; Styles: from n/a through 1.2.3; WordPress Page Builder – Qards: from n/a through 1.0.5; PHPFreeChat: from n/a through 0.2.8; Custom Login Admin Front-end CSS: from n/a through 1.4.1; CSS Adder By Agence-Press: from n/a through 1.5.0; Confirm Data: from n/a through 1.0.7; AMP Toolbox: from n/a through 2.1.1; Admin CSS MU: from n/a through 2.6.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 19 janv. 2024
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- millionclues admin css mu
- deano amp toolbox
- unihost confirm data
- agence-press css adder
- millionclues custom login admin front-end css
- montonio montonio for woocommerce
- frumph phpfreechat
- designmodo qards
- paulclark styles
- squidesma theme minifier
- longwatchstudio woosupply
- longwatchstudio woovip
- longwatchstudio woovirtualwallet
- arcstone amo for wp - membership management
- wpopal wpopal core features
Références
- Fiche CVE-2022-40700 sur le NVD (NIST)
- patchstack.com/database/vulnerability/admin…
- patchstack.com/database/vulnerability/amp…
- patchstack.com/database/vulnerability/confirm…
- patchstack.com/database/vulnerability/css…
- patchstack.com/database/vulnerability/custom…
- patchstack.com/database/vulnerability/montonio…
- patchstack.com/database/vulnerability/phpfreechat/wordpress…
- patchstack.com/database/vulnerability/qards…
- patchstack.com/database/vulnerability/styles/wordpress…
- patchstack.com/database/vulnerability/theme…
- patchstack.com/database/vulnerability/woosupply/wordpress…
- patchstack.com/database/vulnerability/woovip/wordpress…
- patchstack.com/database/vulnerability/woovirtualwallet/wordpr…
- patchstack.com/database/vulnerability/wp…
- patchstack.com/database/vulnerability/wpopal…