Ciphercoin's vulnerability portfolio is concentrated in WordPress plugins, particularly those providing contact forms, login management, and access controls, serving a modestly represented but operationally prominent segment of web application infrastructure. Vulnerabilities affecting these plugins skew toward serious outcomes and recur through web-layer weakness classes including cross-site scripting, CSRF, authentication bypass, and injection flaws that are characteristic of form-handling and access-control code. Defenders should treat updates to these plugins as priority maintenance points for WordPress installations; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ciphercoin over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3634CRITICAL The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection | Nov 21, 2022 | 9.8 | 33 | NO | NO |
CVE-2021-36886HIGH Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.5.9). | Dec 22, 2021 | 8.8 | 28 | NO | NO |
CVE-2022-4303HIGH The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP | Jan 23, 2023 | 7.5 | 25 | NO | NO |
CVE-2021-24144HIGH Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV f | Mar 18, 2021 | 7.8 | 25 | NO | NO |
CVE-2023-31075HIGH Cross-Site Request Forgery (CSRF) vulnerability in Arshid Easy Hide Login.This issue affects Easy Hide Login: from n/a through 1.0.8. | Nov 18, 2023 | 8.8 | 24 | NO | NO |
CVE-2021-36885MEDIUM Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.6.1). | Dec 22, 2021 | 6.1 | 22 | NO | NO |
CVE-2015-6829HIGH Multiple SQL injection vulnerabilities in the getip function in wp-limit-login-attempts.php in the WP Limit Login Attempts plugin before 2.0.1 for WordPress allow remote attackers | Sep 16, 2015 | 7.5 | 21 | NO | NO |
CVE-2025-6740MEDIUM The Contact Form 7 Database Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tmpD’ parameter in all versions up to, and including, 1.3.1 due to insu | Jul 4, 2025 | 6.1 | 19 | NO | NO |
CVE-2023-32505MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Arshid Easy Hide Login plugin <= 1.0.7 versions. | Aug 23, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ciphercoin.
Media articles that mention a CVE ID that affects a product developed by Ciphercoin — matched by CVE ID, not by vendor name.