Ok, so, we answered me it's not the role of CVE version.
By the way, on your site, you wrote "Update the extension to version 4.0.12 or later to fix this issue." (good).
But in below box, you wrote "No fix is available yet"...
Conflicting information. ;-)