Voidcoders' vulnerability footprint centers on WordPress plugins and page-builder extensions, including the Void Contact Form 7 Widget for Elementor and WPBakery Visual Composer integrations, which serve as front-end customization points for small-to-medium website deployments. The recurring exposure reflects application-layer weaknesses common to web plugins: cross-site scripting through improper input neutralization, cross-site request forgery, and missing authorization checks that arise from the plugin architecture's integration with broader WordPress ecosystems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Voidcoders over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47166HIGH Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions. | Mar 13, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-52214HIGH Missing Authorization vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder.This issue affects Void Contact Form 7 Widget For Elementor Page Builder: fr | Mar 26, 2024 | 8.8 | 22 | NO | NO |
CVE-2024-5419MEDIUM The Void Contact Form 7 Widget For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cf7_redirect_page' attribute within the plugin' | Jul 2, 2024 | 5.4 | 19 | NO | NO |
CVE-2024-10172MEDIUM The WPBakery Visual Composer WHMCS Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's void_wbwhmcse_laouts_search shortcode in all versions | Nov 21, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-43291MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder allows | Aug 18, 2024 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Voidcoders.
Media articles that mention a CVE ID that affects a product developed by Voidcoders — matched by CVE ID, not by vendor name.