Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Usabilitydynamics

First CVE: Sep 20, 2019Active for: 7 yearsTotal CVEs: 8

Usabilitydynamics develops a focused suite of WordPress plugins—principally WP Invoice and WP CRM—that handle billing, customer relationship management, and sensitive configuration for WordPress-based businesses. The vendor's vulnerability profile concentrates on application-layer and permission-handling weaknesses, including cross-site request forgery, improper privilege management, and data-exposure flaws characteristic of WordPress plugin architectures where user input handling and role-based access controls recur as pain points. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Usabilitydynamics over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 20, 2019
6 years ago
Most Recent CVE
Jan 16, 2024
920 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-1202HIGH
The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.
Jun 13, 20227.822NONO
CVE-2016-11011MEDIUM
The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
Sep 20, 20196.520NONO
CVE-2022-1617MEDIUM
The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowin
Jan 16, 20246.119NONO
CVE-2016-11008MEDIUM
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.
Sep 20, 20195.319NONO
CVE-2016-11007MEDIUM
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.
Sep 20, 20195.319NONO
CVE-2016-11006MEDIUM
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.
Sep 20, 20195.319NONO
CVE-2016-11010MEDIUM
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.
Sep 20, 20195.318NONO
CVE-2016-11009MEDIUM
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.
Sep 20, 20195.318NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
88%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required2 (25.0%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None7 (87.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Usabilitydynamics.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Usabilitydynamics — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Usabilitydynamics's Products

View all 2 CNAs →

Top CWEs