ayecode records
21 published records for vendor ayecode.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 47.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-862 Missing Authorization3
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-340 Generation of Predictable Numbers or Identifiers1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2024-6265Proof of concept | UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sortayecode · userswp · CWE-89 | Critical9.8 | — | 2.4% | Jun 29, 2024 |
40Plan | CVE-2021-24361No exploit | GeoDirectory Location Manager < 2.1.0.10 - Multiple Unauthenticated SQL Injectionsayecode · location manager · CWE-89 | Critical9.8 | — | 1.8% | Jun 21, 2021 |
35Monitor | CVE-2022-47442No exploit | WordPress UsersWP Plugin <= 1.2.3.9 is vulnerable to CSV Injectionayecode · userswp · CWE-1236 | High8.8 | — | 0.7% | Nov 7, 2023 |
35Monitor | CVE-2024-43973No exploit | WordPress GetPaid plugin <= 2.8.11 - Broken Access Control vulnerabilityayecode · getpaid · CWE-862 | High8.8 | — | 0.5% | Nov 1, 2024 |
35Monitor | CVE-2024-43145No exploit | WordPress GeoDirectory plugin <= 2.3.61 - SQL Injection vulnerabilityayecode · geodirectory · CWE-89 | High8.8 | — | 0.4% | Aug 18, 2024 |
35Monitor | CVE-2024-43981No exploit | WordPress GeoDirectory plugin <= 2.3.70 - Broken Access Control vulnerabilityayecode · geodirectory · CWE-862 | High8.8 | — | 0.4% | Nov 1, 2024 |
30Monitor | CVE-2024-6477No exploit | UsersWP < 1.2.12 - Users Information Disclosureayecode · userswp · CWE-340 | High7.5 | — | 0.6% | Aug 3, 2024 |
28Monitor | CVE-2023-50845No exploit | WordPress GeoDirectory Plugin <= 2.3.28 is vulnerable to SQL Injectionayecode · geodirectory · CWE-89 | High7.2 | — | 0.5% | Dec 28, 2023 |
25Monitor | CVE-2024-2423No exploit | UsersWP <= 1.2.6 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcodeayecode · userswp · CWE-79 | Medium6.4 | — | 0.4% | Apr 9, 2024 |
24Monitor | CVE-2023-2813Proof of concept | Multiple Themes - Reflected XSSajaydsouza · connections reloaded · CWE-79 | Medium6.1 | — | 1.0% | Sep 4, 2023 |
23Monitor | CVE-2025-6200No exploit | GeoDirectory < 2.8.120 - Contributor+ Stored XSSayecode · geodirectory · CWE-79 | Medium5.9 | — | 0.2% | Jul 11, 2025 |
21Monitor | CVE-2021-24720No exploit | GeoDirectory < 2.1.1.3 - Authenticated Stored Cross-Site Scripting (XSS)ayecode · geodirectory · CWE-79 | Medium5.4 | — | 0.9% | Oct 11, 2021 |
21Monitor | CVE-2021-24369No exploit | GetPaid < 2.3.4 - Authenticated Stored XSSayecode · getpaid · CWE-79 | Medium5.4 | — | 0.6% | Jun 21, 2021 |
21Monitor | CVE-2022-4775No exploit | GeoDirectory < 2.2.22 - Contributor+ Stored XSS via Shortcodeayecode · geodirectory · CWE-79 | Medium5.4 | — | 0.5% | Jan 23, 2023 |
21Monitor | CVE-2024-43277No exploit | WordPress UsersWP plugin <= 1.2.15 - Broken Access Control vulnerabilityayecode ltd · userswp · CWE-862 | Medium5.3 | — | 0.4% | Nov 1, 2024 |
21Monitor | CVE-2024-56259No exploit | WordPress GeoDirectory plugin <= 2.3.84 - Cross Site Scripting (XSS) vulnerabilityayecode · geodirectory · CWE-79 | Medium5.4 | — | 0.3% | Jan 2, 2025 |
21Monitor | CVE-2024-3732No exploit | GeoDirectory – WordPress Business Directory Plugin, or Classified Directory <= 2.3.48 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'gd_single_ayecode · geodirectory · CWE-79 | Medium5.4 | — | 0.3% | Apr 23, 2024 |
21Monitor | CVE-2024-50437No exploit | WordPress GeoDirectory plugin <= 2.3.80 - Cross Site Scripting (XSS) vulnerabilityayecode · geodirectory · CWE-79 | Medium5.4 | — | 0.2% | Oct 28, 2024 |
21Monitor | CVE-2024-13590No exploit | Ketchup Shortcodes <= 0.1.2 - Authenticated (Contributor+) Stored Cross-Site Scriptingayecode · ketchup shortcodes · CWE-79 | Medium5.4 | — | 0.2% | Jan 22, 2025 |
17Monitor | CVE-2022-0442No exploit | UsersWP < 1.2.3.1 - Subscriber+ User Avatar Overrideayecode · userswp · CWE-639 | Medium4.3 | — | 0.7% | Mar 7, 2022 |
17Monitor | CVE-2022-29453No exploit | WordPress API KEY for Google Maps plugin <= 1.2.1 - CSRF vulnerability leading to Google Maps API key updateayecode · api key for google maps · CWE-352 | Medium4.3 | — | 0.4% | Jun 15, 2022 |
- CVE-2024-626540Plan
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sort
CriticalCVSS 9.8Proof of conceptEPSS 2%ayecode · userswpJun 29, 2024
- CVE-2021-2436140Plan
GeoDirectory Location Manager < 2.1.0.10 - Multiple Unauthenticated SQL Injections
CriticalCVSS 9.8No exploitEPSS 2%ayecode · location managerJun 21, 2021
- CVE-2022-4744235Monitor
WordPress UsersWP Plugin <= 1.2.3.9 is vulnerable to CSV Injection
HighCVSS 8.8No exploitEPSS 1%ayecode · userswpNov 7, 2023
- CVE-2024-4397335Monitor
WordPress GetPaid plugin <= 2.8.11 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%ayecode · getpaidNov 1, 2024
- CVE-2024-4314535Monitor
WordPress GeoDirectory plugin <= 2.3.61 - SQL Injection vulnerability
HighCVSS 8.8No exploitEPSS 0%ayecode · geodirectoryAug 18, 2024
- CVE-2024-4398135Monitor
WordPress GeoDirectory plugin <= 2.3.70 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%ayecode · geodirectoryNov 1, 2024
- CVE-2024-647730Monitor
UsersWP < 1.2.12 - Users Information Disclosure
HighCVSS 7.5No exploitEPSS 1%ayecode · userswpAug 3, 2024
- CVE-2023-5084528Monitor
WordPress GeoDirectory Plugin <= 2.3.28 is vulnerable to SQL Injection
HighCVSS 7.2No exploitEPSS 1%ayecode · geodirectoryDec 28, 2023
- CVE-2024-242325Monitor
UsersWP <= 1.2.6 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 6.4No exploitEPSS 0%ayecode · userswpApr 9, 2024
- CVE-2023-281324Monitor
Multiple Themes - Reflected XSS
MediumCVSS 6.1Proof of conceptEPSS 1%ajaydsouza · connections reloadedSep 4, 2023
- CVE-2025-620023Monitor
GeoDirectory < 2.8.120 - Contributor+ Stored XSS
MediumCVSS 5.9No exploitEPSS 0%ayecode · geodirectoryJul 11, 2025
- CVE-2021-2472021Monitor
GeoDirectory < 2.1.1.3 - Authenticated Stored Cross-Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 1%ayecode · geodirectoryOct 11, 2021
- CVE-2021-2436921Monitor
GetPaid < 2.3.4 - Authenticated Stored XSS
MediumCVSS 5.4No exploitEPSS 1%ayecode · getpaidJun 21, 2021
- CVE-2022-477521Monitor
GeoDirectory < 2.2.22 - Contributor+ Stored XSS via Shortcode
MediumCVSS 5.4No exploitEPSS 0%ayecode · geodirectoryJan 23, 2023
- CVE-2024-4327721Monitor
WordPress UsersWP plugin <= 1.2.15 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%ayecode ltd · userswpNov 1, 2024
- CVE-2024-5625921Monitor
WordPress GeoDirectory plugin <= 2.3.84 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%ayecode · geodirectoryJan 2, 2025
- CVE-2024-373221Monitor
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory <= 2.3.48 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'gd_single_
MediumCVSS 5.4No exploitEPSS 0%ayecode · geodirectoryApr 23, 2024
- CVE-2024-5043721Monitor
WordPress GeoDirectory plugin <= 2.3.80 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%ayecode · geodirectoryOct 28, 2024
- CVE-2024-1359021Monitor
Ketchup Shortcodes <= 0.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%ayecode · ketchup shortcodesJan 22, 2025
- CVE-2022-044217Monitor
UsersWP < 1.2.3.1 - Subscriber+ User Avatar Override
MediumCVSS 4.3No exploitEPSS 1%ayecode · userswpMar 7, 2022
- CVE-2022-2945317Monitor
WordPress API KEY for Google Maps plugin <= 1.2.1 - CSRF vulnerability leading to Google Maps API key update
MediumCVSS 4.3No exploitEPSS 0%ayecode · api key for google mapsJun 15, 2022