Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2022-40700

8.2 · HIGH
Published Jan 19, 2024 millionclues CWE-918 EPSS 1.00% (60th pctl)

Overview

CVE-2022-40700 is a high-severity vulnerability affecting millionclues admin_css_mu. It was published on January 19, 2024 and has a CVSS 3.1 base score of 8.2 (HIGH).

This vulnerability has a CVSS 3.1 base score of 8.2, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long Watch Studio WooSupply – Suppliers, Supply Orders and Stock Management, Squidesma Theme Minifier, Paul Clark Styles styles, Designmodo Inc. WordPress Page Builder – Qards, Philip M. Hofer (Frumph) PHPFreeChat, Arun Basil Lal Custom Login Admin Front-end CSS, Team Agence-Press CSS Adder By Agence-Press, Unihost Confirm Data, deano1987 AMP Toolbox amp-toolbox, Arun Basil Lal Admin CSS MU.This issue affects Montonio for WooCommerce: from n/a through 6.0.1; Wpopal Core Features: from n/a through 1.5.8; ArcStone: from n/a through 4.6.6; WooVirtualWallet – A virtual wallet for WooCommerce: from n/a through 2.2.1; WooVIP – Membership plugin for WordPress and WooCommerce: from n/

Remediation

Check the references section for vendor advisories and patches from millionclues. Update admin_css_mu to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
millionclues admin_css_mu 0 Affected
deano amp_toolbox 0 Affected
unihost confirm_data 0 Affected
agence-press css_adder 0 Affected
millionclues custom_login_admin_front-end_css 0 Affected
montonio montonio_for_woocommerce 0 Affected
frumph phpfreechat 0 Affected
designmodo qards 0 Affected
paulclark styles 0 Affected
squidesma theme_minifier 0 Affected
longwatchstudio woosupply 0 Affected
longwatchstudio woovip 0 Affected
longwatchstudio woovirtualwallet 0 Affected
arcstone amo_for_wp_-_membership_management 0 Affected
wpopal wpopal_core_features 0 Affected

Frequently Asked Questions

What is CVE-2022-40700?

CVE-2022-40700 is a high-severity vulnerability affecting millionclues admin_css_mu. It was published on January 19, 2024 and has a CVSS 3.1 base score of 8.2 (HIGH).

How severe is CVE-2022-40700?

This vulnerability has a CVSS 3.1 base score of 8.2, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2022-40700?

Check the references section for vendor advisories and patches from millionclues. Update admin_css_mu to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2022-40700?

CyberStrike's AI-powered security agents can automatically detect CVE-2022-40700 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.