Usabilitydynamics develops a focused suite of WordPress plugins—principally WP Invoice and WP CRM—that handle billing, customer relationship management, and sensitive configuration for WordPress-based businesses. The vendor's vulnerability profile concentrates on application-layer and permission-handling weaknesses, including cross-site request forgery, improper privilege management, and data-exposure flaws characteristic of WordPress plugin architectures where user input handling and role-based access controls recur as pain points. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Usabilitydynamics over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1202HIGH The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability. | Jun 13, 2022 | 7.8 | 22 | NO | NO |
CVE-2016-11011MEDIUM The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation. | Sep 20, 2019 | 6.5 | 20 | NO | NO |
CVE-2022-1617MEDIUM The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowin | Jan 16, 2024 | 6.1 | 19 | NO | NO |
CVE-2016-11008MEDIUM The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates. | Sep 20, 2019 | 5.3 | 19 | NO | NO |
CVE-2016-11007MEDIUM The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval. | Sep 20, 2019 | 5.3 | 19 | NO | NO |
CVE-2016-11006MEDIUM The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes. | Sep 20, 2019 | 5.3 | 19 | NO | NO |
CVE-2016-11010MEDIUM The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates. | Sep 20, 2019 | 5.3 | 18 | NO | NO |
CVE-2016-11009MEDIUM The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates. | Sep 20, 2019 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Usabilitydynamics.
Media articles that mention a CVE ID that affects a product developed by Usabilitydynamics — matched by CVE ID, not by vendor name.