Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2022-40700

PUBLISHED 13.11.2024

CNA: Patchstack

Server Side Request Forgery (SSRF) vulnerability affecting multiple WordPress plugins

Обновлено: 19.01.2024
Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long Watch Studio WooSupply – Suppliers, Supply Orders and Stock Management, Squidesma Theme Minifier, Paul Clark Styles styles, Designmodo Inc. WordPress Page Builder – Qards, Philip M. Hofer (Frumph) PHPFreeChat, Arun Basil Lal Custom Login Admin Front-end CSS, Team Agence-Press CSS Adder By Agence-Press, Unihost Confirm Data, deano1987 AMP Toolbox amp-toolbox, Arun Basil Lal Admin CSS MU.This issue affects Montonio for WooCommerce: from n/a through 6.0.1; Wpopal Core Features: from n/a through 1.5.8; ArcStone: from n/a through 4.6.6; WooVirtualWallet – A virtual wallet for WooCommerce: from n/a through 2.2.1; WooVIP – Membership plugin for WordPress and WooCommerce: from n/a through 1.4.4; WooSupply – Suppliers, Supply Orders and Stock Management: from n/a through 1.2.2; Theme Minifier: from n/a through 2.0; Styles: from n/a through 1.2.3; WordPress Page Builder – Qards: from n/a through 1.0.5; PHPFreeChat: from n/a through 0.2.8; Custom Login Admin Front-end CSS: from n/a through 1.4.1; CSS Adder By Agence-Press: from n/a through 1.5.0; Confirm Data: from n/a through 1.0.7; AMP Toolbox: from n/a through 2.1.1; Admin CSS MU: from n/a through 2.6.

CWE

Идентификатор Описание
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

CVSS

Оценка Severity Версия Базовый вектор
8.2 HIGH 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Доп. Информация

Product Status

Montonio for WooCommerce
Product: Montonio for WooCommerce
Vendor: Montonio
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 6.0.1 affected
Wpopal Core Features
Product: Wpopal Core Features
Vendor: Wpopal
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 1.5.8 affected
ArcStone
Product: ArcStone
Vendor: AMO for WP – Membership Management
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 4.6.6 affected
WooVirtualWallet – A virtual wallet for WooCommerce
Product: WooVirtualWallet – A virtual wallet for WooCommerce
Vendor: Long Watch Studio
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 2.2.1 affected
WooVIP – Membership plugin for WordPress and WooCommerce
Product: WooVIP – Membership plugin for WordPress and WooCommerce
Vendor: Long Watch Studio
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 1.4.4 affected
WooSupply – Suppliers, Supply Orders and Stock Management
Product: WooSupply – Suppliers, Supply Orders and Stock Management
Vendor: Long Watch Studio
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 1.2.2 affected
Theme Minifier
Product: Theme Minifier
Vendor: Squidesma
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 2.0 affected
Styles
Product: Styles
Vendor: Paul Clark
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 1.2.3 affected
WordPress Page Builder – Qards
Product: WordPress Page Builder – Qards
Vendor: Designmodo Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 1.0.5 affected
PHPFreeChat
Product: PHPFreeChat
Vendor: Philip M. Hofer (Frumph)
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 0.2.8 affected
Custom Login Admin Front-end CSS
Product: Custom Login Admin Front-end CSS
Vendor: Arun Basil Lal
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 1.4.1 affected
CSS Adder By Agence-Press
Product: CSS Adder By Agence-Press
Vendor: Team Agence-Press
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 1.5.0 affected
Confirm Data
Product: Confirm Data
Vendor: Unihost
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 1.0.7 affected
AMP Toolbox
Product: AMP Toolbox
Vendor: deano1987
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 2.1.1 affected
Admin CSS MU
Product: Admin CSS MU
Vendor: Arun Basil Lal
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 2.6 affected
 

Ссылки

https://patchstack.com/database/vulnerability/montonio-for-woocommerce/wordpress-montonio-for-woocommerce-plugin-6-0-1-s...
https://patchstack.com/database/vulnerability/wpopal-core-features/wordpress-wpopal-core-features-plugin-1-5-7-server-si...
https://patchstack.com/database/vulnerability/wp-amo/wordpress-amo-for-wp-plugin-4-6-6-server-side-request-forgery-ssrf?...
https://patchstack.com/database/vulnerability/woovirtualwallet/wordpress-woovirtualwallet-plugin-2-2-1-server-side-reque...
https://patchstack.com/database/vulnerability/woovip/wordpress-woovip-plugin-1-4-4-server-side-request-forgery-ssrf?_s_i...
https://patchstack.com/database/vulnerability/woosupply/wordpress-woosupply-plugin-1-2-2-server-side-request-forgery-ssr...
https://patchstack.com/database/vulnerability/theme-minifier/wordpress-theme-minifier-plugin-2-0-server-side-request-for...
https://patchstack.com/database/vulnerability/styles/wordpress-styles-plugin-1-2-3-server-side-request-forgery-ssrf?_s_i...
https://patchstack.com/database/vulnerability/qards-free/wordpress-wordpress-page-builder-qards-plugin-1-0-5-server-side...
https://patchstack.com/database/vulnerability/phpfreechat/wordpress-phpfreechat-plugin-0-2-8-server-side-request-forgery...
https://patchstack.com/database/vulnerability/custom-login-admin-front-end-css-with-multisite-support/wordpress-custom-l...
https://patchstack.com/database/vulnerability/css-adder-by-agence-press/wordpress-css-adder-by-agene-press-plugin-1-5-0-...
https://patchstack.com/database/vulnerability/confirm-data/wordpress-confirm-data-plugin-1-0-7-unauth-server-side-reques...
https://patchstack.com/database/vulnerability/amp-toolbox/wordpress-amp-toolbox-plugin-2-1-1-server-side-request-forgery...
https://patchstack.com/database/vulnerability/admin-css-mu/wordpress-admin-css-mu-plugin-2-6-server-side-request-forgery...

CVE Program Container

Обновлено: 03.08.2024
SSVC and KEV, plus CVSS and CWE if not provided by the CNA.

Ссылки

https://patchstack.com/database/vulnerability/montonio-for-woocommerce/wordpress-montonio-for-woocommerce-plugin-6-0-1-s...
https://patchstack.com/database/vulnerability/wpopal-core-features/wordpress-wpopal-core-features-plugin-1-5-7-server-si...
https://patchstack.com/database/vulnerability/wp-amo/wordpress-amo-for-wp-plugin-4-6-6-server-side-request-forgery-ssrf?...
https://patchstack.com/database/vulnerability/woovirtualwallet/wordpress-woovirtualwallet-plugin-2-2-1-server-side-reque...
https://patchstack.com/database/vulnerability/woovip/wordpress-woovip-plugin-1-4-4-server-side-request-forgery-ssrf?_s_i...
https://patchstack.com/database/vulnerability/woosupply/wordpress-woosupply-plugin-1-2-2-server-side-request-forgery-ssr...
https://patchstack.com/database/vulnerability/theme-minifier/wordpress-theme-minifier-plugin-2-0-server-side-request-for...
https://patchstack.com/database/vulnerability/styles/wordpress-styles-plugin-1-2-3-server-side-request-forgery-ssrf?_s_i...
https://patchstack.com/database/vulnerability/qards-free/wordpress-wordpress-page-builder-qards-plugin-1-0-5-server-side...
https://patchstack.com/database/vulnerability/phpfreechat/wordpress-phpfreechat-plugin-0-2-8-server-side-request-forgery...
https://patchstack.com/database/vulnerability/custom-login-admin-front-end-css-with-multisite-support/wordpress-custom-l...
https://patchstack.com/database/vulnerability/css-adder-by-agence-press/wordpress-css-adder-by-agene-press-plugin-1-5-0-...
https://patchstack.com/database/vulnerability/confirm-data/wordpress-confirm-data-plugin-1-0-7-unauth-server-side-reques...
https://patchstack.com/database/vulnerability/amp-toolbox/wordpress-amp-toolbox-plugin-2-1-1-server-side-request-forgery...
https://patchstack.com/database/vulnerability/admin-css-mu/wordpress-admin-css-mu-plugin-2-6-server-side-request-forgery...

CISA ADP Vulnrichment

Обновлено: 13.11.2024
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
none yes total 2.0.3 13.11.2024

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.