Coffee2code develops a portfolio of WordPress plugins focused on user engagement and site management features, including tools for commenter notifications, post-limiting, update suppression, and authentication controls. The observed vulnerability pattern centers on sensitive-information exposure, including improper handling of formula elements in exported data and information disclosure through error messages, reflecting the data-handling and configuration-visibility surface typical of WordPress extensions. Current exposure counts and severity details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Coffee2code over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45360CRITICAL Improper Neutralization of Formula Elements in a CSV File vulnerability in Scott Reilly Commenter Emails.This issue affects Commenter Emails: from n/a through 2.6.1. | Nov 7, 2023 | 9.8 | 25 | NO | NO |
CVE-2024-6544MEDIUM The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions up to, and including, 4.4.1. This is due to the plugin utilizing bootstrap and lea | Sep 13, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-7415MEDIUM The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the plugin allowing direct access to | Sep 6, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-7412MEDIUM The No Update Nag plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.12. This is due to the plugin allowing direct access to the b | Aug 12, 2024 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Coffee2code.
Media articles that mention a CVE ID that affects a product developed by Coffee2code — matched by CVE ID, not by vendor name.