2code is a web application and plugin vendor whose portfolio focuses on WordPress-based solutions and community platforms such as WPQA Builder, Himer, Discy, and Ask Me. The vendor's vulnerability profile is marked by a durable concentration in web-application authentication, authorization, and input-handling flaws—including cross-site request forgery, cross-site scripting, user-controlled authorization bypass, and improper authentication mechanisms—which are characteristic of interpreted web codebases with complex permission models. These weakness classes typically arise in the context of plugins and add-on frameworks where permission validation and output encoding must span user-supplied content and role-based access control. The recurring pattern suggests that defenders should prioritize patches addressing authorization and input validation when tracking this vendor's advisories, particularly in environments where multiple plugins compose the application layer. Current vulnerability severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 2code over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1598MEDIUM The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover p | Jun 8, 2022 | 5.3 | 31 | NO | YES |
CVE-2022-1597MEDIUM The WPQA Builder WordPress plugin before 5.4, used as a companion for the Discy and Himer , does not sanitise and escape a parameter on its reset password form which makes it possi | Jun 8, 2022 | 6.1 | 29 | NO | YES |
CVE-2022-3688HIGH The WPQA Builder WordPress plugin before 5.9 does not have CSRF check when following and unfollowing users, which could allow attackers to make logged in users perform such actions | Nov 21, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-2232HIGH The lacks CSRF checks allowing a user to invite any user to any group (including private groups) | Aug 5, 2024 | 8.1 | 24 | NO | NO |
CVE-2024-2376HIGH The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attac | Jul 3, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-2231MEDIUM The allows any authenticated user to join a private group due to a missing authorization check on a function | Jul 3, 2024 | 6.5 | 21 | NO | NO |
CVE-2022-1051MEDIUM The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phone or profile credentials fields | May 16, 2022 | 5.4 | 21 | NO | NO |
CVE-2022-1241MEDIUM The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile page, leading to Reflected Cross-Site Scripting issues | Jun 8, 2022 | 6.1 | 19 | NO | NO |
CVE-2022-1424MEDIUM The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their | Jun 8, 2022 | 6.5 | 18 | NO | NO |
CVE-2022-1422MEDIUM The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings | Jun 8, 2022 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 2code.
Media articles that mention a CVE ID that affects a product developed by 2code — matched by CVE ID, not by vendor name.