Ayecode develops a portfolio of WordPress plugins and extensions serving niche functions across directory listings, user management, payment processing, and geolocation features, with a presence among the more prominent WordPress-adjacent vendors tracked. Vulnerabilities affecting the vendor carry a meaningful share toward serious outcomes and a moderate tendency toward public exploit availability, concentrating in application-layer input-handling and authorization weaknesses typical of server-side PHP codebases. The recurring exposure centers on plugins such as GeoDirectory, UsersWP, and GetPaid through weakness classes including cross-site scripting, SQL injection, missing authorization, and CSRF that reflect the common attack surface of WordPress plugins handling user input and administrative functions. Defenders should prioritize patching these plugins in multi-site WordPress installations where they manage sensitive user and transaction data; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ayecode over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6265CRITICAL The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the | Jun 29, 2024 | 9.8 | 41 | NO | YES |
CVE-2021-24361CRITICAL In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then | Jun 21, 2021 | 9.8 | 28 | NO | NO |
CVE-2024-43145HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode Ltd GeoDirectory.This issue affects GeoDirectory: from n/a through 2.3 | Aug 18, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-2813MEDIUM All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business | Sep 4, 2023 | 6.1 | 25 | NO | YES |
CVE-2024-43973HIGH Missing Authorization vulnerability in Stiofan GetPaid invoicing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GetPaid: from n/a throug | Nov 1, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-43981HIGH Missing Authorization vulnerability in AyeCode – WP Business Directory Plugins GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec | Nov 1, 2024 | 8.8 | 23 | NO | NO |
CVE-2022-47442HIGH Improper Neutralization of Formula Elements in a CSV File vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a through 1.2.3.9. | Nov 7, 2023 | 8.8 | 23 | NO | NO |
CVE-2024-6477HIGH The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve s | Aug 3, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-50845HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode - WordPress Business Directory Plugins GeoDirectory – WordPress Busine | Dec 28, 2023 | 7.2 | 20 | NO | NO |
CVE-2022-4775MEDIUM The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with | Jan 23, 2023 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ayecode.
Media articles that mention a CVE ID that affects a product developed by Ayecode — matched by CVE ID, not by vendor name.