CVE · High

CVE-2022-40700 — Admin CSS MU [admin-css-mu] < 2.7 (closed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-40700 Admin CSS MU [admin-css-mu] < 2.7 (closed) Server-Side Request Forgery (SSRF) High 8.2 < 2.7 2.7 2023-03-03

CVE-2022-40700

A vulnerability in several WordPress and WooCommerce plugins allows an attacker to make unauthorized requests to internal network resources, potentially leading to sensitive data exposure or system compromise, by manipulating the request target in a way that the application itself would not normally allow. This can be exploited by an attacker who can submit malicious input to the affected plugins, which may not properly validate or sanitize the input. The vulnerability affects a range of plugins, including Montonio for WooCommerce, Wpopal Core Features, and others, across various versions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.