HOMEVULNERABILITIESCVE-2022-40700
CRITICAL

CVE-2022-40700

CWE-918Published: January 19, 2024· Updated: Jun 17, 2026

9.8
CVSS v3.1

Official Description

Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long Watch Studio WooSupply – Suppliers, Supply Orders and Stock Management, Squidesma Theme Minifier, Paul Clark Styles styles, Designmodo Inc. WordPress Page Builder – Qards, Philip M. Hofer (Frumph) PHPFreeChat, Arun Basil Lal Custom Login Admin Front-end CSS, Team Agence-Press CSS Adder By Agence-Press, Unihost Confirm Data, deano1987 AMP Toolbox amp-toolbox, Arun Basil Lal Admin CSS MU.This issue affects Montonio for WooCommerce: from n/a through 6.0.1; Wpopal Core Features: from n/a through 1.5.8; ArcStone: from n/a through 4.6.6; WooVirtualWallet – A virtual wallet for WooCommerce: from n/a through 2.2.1; WooVIP – Membership plugin for WordPress and WooCommerce: from n/a through 1.4.4; WooSupply – Suppliers, Supply Orders and Stock Management: from n/a through 1.2.2; Theme Minifier: from n/a through 2.0; Styles: from n/a through 1.2.3; WordPress Page Builder – Qards: from n/a through 1.0.5; PHPFreeChat: from n/a through 0.2.8; Custom Login Admin Front-end CSS: from n/a through 1.4.1; CSS Adder By Agence-Press: from n/a through 1.5.0; Confirm Data: from n/a through 1.0.7; AMP Toolbox: from n/a through 2.1.1; Admin CSS MU: from n/a through 2.6.

NVD Source

Risk Analysis

Multiple WordPress plugins are affected by a Server-Side Request Forgery (SSRF) vulnerability. This flaw allows remote attackers to force the server to make unauthorized requests, which is critical given the potential for internal network discovery.

No public exploit is known, and it is not in the KEV catalog. The vulnerability is remotely exploitable with low complexity.

Recommended Action

Update all affected WordPress plugins to their latest versions and restrict outbound network access from the web server.

Generated by the CTIWATCH analysis pipeline from this CVE's metadata (CVSS, EPSS, KEV status, exploit intelligence). Verify against vendor advisories before acting.

Technical Analysis

CVE-2022-40700 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.

The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.

A successful exploit results in complete confidentiality breach (data exposure), full integrity compromise (data manipulation), availability disruption (denial of service), with a CVSS base score of 9.8.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorNetwork
Attack ComplexityLow
Privileges Req.None
User InteractionNone
ScopeUnchanged
Impact
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Vendors & Products

agence-press1 product(s)
css adder
arcstone1 product(s)
amo for wp - membership management
deano1 product(s)
amp toolbox
designmodo1 product(s)
qards
frumph1 product(s)
phpfreechat
longwatchstudio3 product(s)
woosupplywoovipwoovirtualwallet
millionclues2 product(s)
admin css mucustom login admin front-end css
montonio1 product(s)
montonio for woocommerce
paulclark1 product(s)
styles
squidesma1 product(s)
theme minifier
unihost1 product(s)
confirm data
wpopal1 product(s)
wpopal core features
Source: NVD CPE · 15 total CPE entries

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

All References (30)

Quick Facts

CVE IDCVE-2022-40700
CVSS Score9.8 / 10
SeverityCRITICAL
WeaknessCWE-918
CISA KEVNo
Affected12 vendor(s)
PublishedJan 19, 2024

Related CVEs (CWE-918)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2022-40700 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.