{"cve":{"cve_id":"CVE-2022-40700","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.00999,"epss_percentile":0.58238,"epss_as_of":"2026-06-23","description":"Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long Watch Studio WooSupply – Suppliers, Supply Orders and Stock Management, Squidesma Theme Minifier, Paul Clark Styles styles, Designmodo Inc. WordPress Page Builder – Qards, Philip M. Hofer (Frumph) PHPFreeChat, Arun Basil Lal Custom Login Admin Front-end CSS, Team Agence-Press CSS Adder By Agence-Press, Unihost Confirm Data, deano1987 AMP Toolbox amp-toolbox, Arun Basil Lal Admin CSS MU.This issue affects Montonio for WooCommerce: from n/a through 6.0.1; Wpopal Core Features: from n/a through 1.5.8; ArcStone: from n/a through 4.6.6; WooVirtualWallet – A virtual wallet for WooCommerce: from n/a through 2.2.1; WooVIP – Membership plugin for WordPress and WooCommerce: from n/a through 1.4.4; WooSupply – Suppliers, Supply Orders and Stock Management: from n/a through 1.2.2; Theme Minifier: from n/a through 2.0; Styles: from n/a through 1.2.3; WordPress Page Builder – Qards: from n/a through 1.0.5; PHPFreeChat: from n/a through 0.2.8; Custom Login Admin Front-end CSS: from n/a through 1.4.1; CSS Adder By Agence-Press: from n/a through 1.5.0; Confirm Data: from n/a through 1.0.7; AMP Toolbox: from n/a through 2.1.1; Admin CSS MU: from n/a through 2.6.","published_at":"2024-01-19T14:30:11.427000Z","last_modified_at":null,"cvss_v3_score":8.2,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","cvss_v3_severity":"HIGH","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":"none","ssvc_automatable":true,"ssvc_technical_impact":"total","cwes":["CWE-918"],"nvd_references":["https://patchstack.com/database/vulnerability/montonio-for-woocommerce/wordpress-montonio-for-woocommerce-plugin-6-0-1-server-side-request-forgery-ssrf?_s_id=cve","https://patchstack.com/database/vulnerability/wpopal-core-features/wordpress-wpopal-core-features-plugin-1-5-7-server-side-request-forgery-ssrf?_s_id=cve","https://patchstack.com/database/vulnerability/wp-amo/wordpress-amo-for-wp-plugin-4-6-6-server-side-request-forgery-ssrf?_s_id=cve","https://patchstack.com/database/vulnerability/woovirtualwallet/wordpress-woovirtualwallet-plugin-2-2-1-server-side-request-forgery-ssrf?_s_id=cve","https://patchstack.com/database/vulnerability/woovip/wordpress-woovip-plugin-1-4-4-server-side-request-forgery-ssrf?_s_id=cve","https://patchstack.com/database/vulnerability/woosupply/wordpress-woosupply-plugin-1-2-2-server-side-request-forgery-ssrf?_s_id=cve","https://patchstack.com/database/vulnerability/theme-minifier/wordpress-theme-minifier-plugin-2-0-server-side-request-forgery-ssrf?_s_id=cve","https://patchstack.com/database/vulnerability/styles/wordpress-styles-plugin-1-2-3-server-side-request-forgery-ssrf?_s_id=cve","https://patchstack.com/database/vulnerability/qards-free/wordpress-wordpress-page-builder-qards-plugin-1-0-5-server-side-request-forgery-ssrf?_s_id=cve","https://patchstack.com/database/vulnerability/phpfreechat/wordpress-phpfreechat-plugin-0-2-8-server-side-request-forgery-ssrf?_s_id=cve","https://patchstack.com/database/vulnerability/custom-login-admin-front-end-css-with-multisite-support/wordpress-custom-login-admin-front-end-css-plugin-1-4-1-server-side-request-forgery-ssrf?_s_id=cve","https://patchstack.com/database/vulnerability/css-adder-by-agence-press/wordpress-css-adder-by-agene-press-plugin-1-5-0-server-side-request-forgery-ssrf?_s_id=cve","https://patchstack.com/database/vulnerability/confirm-data/wordpress-confirm-data-plugin-1-0-7-unauth-server-side-request-forgery-ssrf-vulnerability?_s_id=cve","https://patchstack.com/database/vulnerability/amp-toolbox/wordpress-amp-toolbox-plugin-2-1-1-server-side-request-forgery-ssrf?_s_id=cve","https://patchstack.com/database/vulnerability/admin-css-mu/wordpress-admin-css-mu-plugin-2-6-server-side-request-forgery-ssrf-vulnerability?_s_id=cve"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-06-29T01:17:16.187107Z"},"effective_severity":"HIGH","badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"L","value_label":"Low"},{"metric":"A","name":"Availability","value":"N","value_label":"None"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"amo-for-wp-membership-management","vendor_name":"AMO for WP – Membership Management","product_slug":"arcstone","product_name":"ArcStone","version_start":"n/a","version_start_inclusive":true,"version_end":"4.6.6","version_end_inclusive":true,"cpe23_uri":"cve5:amo-for-wp-membership-management:arcstone:n/a:4.6.6"},{"vendor_slug":"arun-basil-lal","vendor_name":"Arun Basil Lal","product_slug":"admin-css-mu","product_name":"Admin CSS MU","version_start":"n/a","version_start_inclusive":true,"version_end":"2.6","version_end_inclusive":true,"cpe23_uri":"cve5:arun-basil-lal:admin-css-mu:n/a:2.6"},{"vendor_slug":"arun-basil-lal","vendor_name":"Arun Basil Lal","product_slug":"custom-login-admin-front-end-css","product_name":"Custom Login Admin Front-end CSS","version_start":"n/a","version_start_inclusive":true,"version_end":"1.4.1","version_end_inclusive":true,"cpe23_uri":"cve5:arun-basil-lal:custom-login-admin-front-end-css:n/a:1.4.1"},{"vendor_slug":"deano1987","vendor_name":"deano1987","product_slug":"amp-toolbox","product_name":"AMP Toolbox","version_start":"n/a","version_start_inclusive":true,"version_end":"2.1.1","version_end_inclusive":true,"cpe23_uri":"cve5:deano1987:amp-toolbox:n/a:2.1.1"},{"vendor_slug":"designmodo-inc.","vendor_name":"Designmodo Inc.","product_slug":"wordpress-page-builder-qards","product_name":"WordPress Page Builder – Qards","version_start":"n/a","version_start_inclusive":true,"version_end":"1.0.5","version_end_inclusive":true,"cpe23_uri":"cve5:designmodo-inc.:wordpress-page-builder-qards:n/a:1.0.5"},{"vendor_slug":"long-watch-studio","vendor_name":"Long Watch Studio","product_slug":"woosupply-suppliers-supply-orders-and-stock-management","product_name":"WooSupply – Suppliers, Supply Orders and Stock Management","version_start":"n/a","version_start_inclusive":true,"version_end":"1.2.2","version_end_inclusive":true,"cpe23_uri":"cve5:long-watch-studio:woosupply-suppliers-supply-orders-and-stock-management:n/a:1.2.2"},{"vendor_slug":"long-watch-studio","vendor_name":"Long Watch Studio","product_slug":"woovip-membership-plugin-for-wordpress-and-woocommerce","product_name":"WooVIP – Membership plugin for WordPress and WooCommerce","version_start":"n/a","version_start_inclusive":true,"version_end":"1.4.4","version_end_inclusive":true,"cpe23_uri":"cve5:long-watch-studio:woovip-membership-plugin-for-wordpress-and-woocommerce:n/a:1.4.4"},{"vendor_slug":"long-watch-studio","vendor_name":"Long Watch Studio","product_slug":"woovirtualwallet-a-virtual-wallet-for-woocommerce","product_name":"WooVirtualWallet – A virtual wallet for WooCommerce","version_start":"n/a","version_start_inclusive":true,"version_end":"2.2.1","version_end_inclusive":true,"cpe23_uri":"cve5:long-watch-studio:woovirtualwallet-a-virtual-wallet-for-woocommerce:n/a:2.2.1"},{"vendor_slug":"montonio","vendor_name":"Montonio","product_slug":"montonio-for-woocommerce","product_name":"Montonio for WooCommerce","version_start":"n/a","version_start_inclusive":true,"version_end":"6.0.1","version_end_inclusive":true,"cpe23_uri":"cve5:montonio:montonio-for-woocommerce:n/a:6.0.1"},{"vendor_slug":"paul-clark","vendor_name":"Paul Clark","product_slug":"styles","product_name":"Styles","version_start":"n/a","version_start_inclusive":true,"version_end":"1.2.3","version_end_inclusive":true,"cpe23_uri":"cve5:paul-clark:styles:n/a:1.2.3"},{"vendor_slug":"philip-m.-hofer-frumph","vendor_name":"Philip M. Hofer (Frumph)","product_slug":"phpfreechat","product_name":"PHPFreeChat","version_start":"n/a","version_start_inclusive":true,"version_end":"0.2.8","version_end_inclusive":true,"cpe23_uri":"cve5:philip-m.-hofer-frumph:phpfreechat:n/a:0.2.8"},{"vendor_slug":"squidesma","vendor_name":"Squidesma","product_slug":"theme-minifier","product_name":"Theme Minifier","version_start":"n/a","version_start_inclusive":true,"version_end":"2.0","version_end_inclusive":true,"cpe23_uri":"cve5:squidesma:theme-minifier:n/a:2.0"},{"vendor_slug":"team-agence-press","vendor_name":"Team Agence-Press","product_slug":"css-adder-by-agence-press","product_name":"CSS Adder By Agence-Press","version_start":"n/a","version_start_inclusive":true,"version_end":"1.5.0","version_end_inclusive":true,"cpe23_uri":"cve5:team-agence-press:css-adder-by-agence-press:n/a:1.5.0"},{"vendor_slug":"unihost","vendor_name":"Unihost","product_slug":"confirm-data","product_name":"Confirm Data","version_start":"n/a","version_start_inclusive":true,"version_end":"1.0.7","version_end_inclusive":true,"cpe23_uri":"cve5:unihost:confirm-data:n/a:1.0.7"},{"vendor_slug":"wpopal","vendor_name":"wpopal","product_slug":"wpopal-core-features","product_name":"Wpopal Core Features","version_start":"n/a","version_start_inclusive":true,"version_end":"1.5.8","version_end_inclusive":true,"cpe23_uri":"cve5:wpopal:wpopal-core-features:n/a:1.5.8"}],"exploit_refs":[],"news":[],"references":[{"url":"https://patchstack.com/database/vulnerability/montonio-for-woocommerce/wordpress-montonio-for-woocommerce-plugin-6-0-1-server-side-request-forgery-ssrf?_s_id=cve","source_type":"MISC","tags":[]},{"url":"https://patchstack.com/database/vulnerability/wpopal-core-features/wordpress-wpopal-core-features-plugin-1-5-7-server-side-request-forgery-ssrf?_s_id=cve","source_type":"MISC","tags":[]},{"url":"https://patchstack.com/database/vulnerability/wp-amo/wordpress-amo-for-wp-plugin-4-6-6-server-side-request-forgery-ssrf?_s_id=cve","source_type":"MISC","tags":[]},{"url":"https://patchstack.com/database/vulnerability/woovirtualwallet/wordpress-woovirtualwallet-plugin-2-2-1-server-side-request-forgery-ssrf?_s_id=cve","source_type":"MISC","tags":[]},{"url":"https://patchstack.com/database/vulnerability/woovip/wordpress-woovip-plugin-1-4-4-server-side-request-forgery-ssrf?_s_id=cve","source_type":"MISC","tags":[]},{"url":"https://patchstack.com/database/vulnerability/woosupply/wordpress-woosupply-plugin-1-2-2-server-side-request-forgery-ssrf?_s_id=cve","source_type":"MISC","tags":[]},{"url":"https://patchstack.com/database/vulnerability/theme-minifier/wordpress-theme-minifier-plugin-2-0-server-side-request-forgery-ssrf?_s_id=cve","source_type":"MISC","tags":[]},{"url":"https://patchstack.com/database/vulnerability/styles/wordpress-styles-plugin-1-2-3-server-side-request-forgery-ssrf?_s_id=cve","source_type":"MISC","tags":[]},{"url":"https://patchstack.com/database/vulnerability/qards-free/wordpress-wordpress-page-builder-qards-plugin-1-0-5-server-side-request-forgery-ssrf?_s_id=cve","source_type":"MISC","tags":[]},{"url":"https://patchstack.com/database/vulnerability/phpfreechat/wordpress-phpfreechat-plugin-0-2-8-server-side-request-forgery-ssrf?_s_id=cve","source_type":"MISC","tags":[]},{"url":"https://patchstack.com/database/vulnerability/custom-login-admin-front-end-css-with-multisite-support/wordpress-custom-login-admin-front-end-css-plugin-1-4-1-server-side-request-forgery-ssrf?_s_id=cve","source_type":"MISC","tags":[]},{"url":"https://patchstack.com/database/vulnerability/css-adder-by-agence-press/wordpress-css-adder-by-agene-press-plugin-1-5-0-server-side-request-forgery-ssrf?_s_id=cve","source_type":"MISC","tags":[]},{"url":"https://patchstack.com/database/vulnerability/confirm-data/wordpress-confirm-data-plugin-1-0-7-unauth-server-side-request-forgery-ssrf-vulnerability?_s_id=cve","source_type":"MISC","tags":[]},{"url":"https://patchstack.com/database/vulnerability/amp-toolbox/wordpress-amp-toolbox-plugin-2-1-1-server-side-request-forgery-ssrf?_s_id=cve","source_type":"MISC","tags":[]},{"url":"https://patchstack.com/database/vulnerability/admin-css-mu/wordpress-admin-css-mu-plugin-2-6-server-side-request-forgery-ssrf-vulnerability?_s_id=cve","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2024-01-19T14:30:11.427000Z","label":"CVE published","source":null},{"type":"cvss_changed","at":"2026-06-28T17:23:48.279798Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:23:48.279798Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:23:48.279798Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"ssvc_changed","at":"2026-06-29T01:17:16.187107Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T01:17:16.187107Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T01:17:16.187107Z","label":"SSVC decision revised","source":"vulnrichment"}]}