Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ayecode

First CVE: Jun 21, 2021Active for: 5 yearsTotal CVEs: 21
24.5
VTI Score
Low

Ayecode develops a portfolio of WordPress plugins and extensions serving niche functions across directory listings, user management, payment processing, and geolocation features, with a presence among the more prominent WordPress-adjacent vendors tracked. Vulnerabilities affecting the vendor carry a meaningful share toward serious outcomes and a moderate tendency toward public exploit availability, concentrating in application-layer input-handling and authorization weaknesses typical of server-side PHP codebases. The recurring exposure centers on plugins such as GeoDirectory, UsersWP, and GetPaid through weakness classes including cross-site scripting, SQL injection, missing authorization, and CSRF that reflect the common attack surface of WordPress plugins handling user input and administrative functions. Defenders should prioritize patching these plugins in multi-site WordPress installations where they manage sensitive user and transaction data; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ayecode over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 21, 2021
5 years ago
Most Recent CVE
Jul 11, 2025
378 days ago

Products(12 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-6265CRITICAL
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the
Jun 29, 20249.841NOYES
CVE-2021-24361CRITICAL
In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then
Jun 21, 20219.828NONO
CVE-2024-43145HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode Ltd GeoDirectory.This issue affects GeoDirectory: from n/a through 2.3
Aug 18, 20248.825NONO
CVE-2023-2813MEDIUM
All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business
Sep 4, 20236.125NOYES
CVE-2024-43973HIGH
Missing Authorization vulnerability in Stiofan GetPaid invoicing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GetPaid: from n/a throug
Nov 1, 20248.824NONO
CVE-2024-43981HIGH
Missing Authorization vulnerability in AyeCode – WP Business Directory Plugins GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affec
Nov 1, 20248.823NONO
CVE-2022-47442HIGH
Improper Neutralization of Formula Elements in a CSV File vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a through 1.2.3.9.
Nov 7, 20238.823NONO
CVE-2024-6477HIGH
The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve s
Aug 3, 20247.522NONO
CVE-2023-50845HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode - WordPress Business Directory Plugins GeoDirectory – WordPress Busine
Dec 28, 20237.220NONO
CVE-2022-4775MEDIUM
The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with
Jan 23, 20235.420NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
62%
29%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (42.9%)
Unknown0 (0.0%)
Required12 (57.1%)
Privileges Required
Low13 (61.9%)
High2 (9.5%)
None6 (28.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
9.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ayecode.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ayecode — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ayecode's Products

View all 3 CNAs →

Top CWEs