ayecode CVE Vulnerabilities & Metrics

Focus on ayecode vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About ayecode Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with ayecode. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total ayecode CVEs: 11
Earliest CVE date: 21 Jun 2021, 20:15 UTC
Latest CVE date: 01 Nov 2024, 15:15 UTC

Latest CVE reference: CVE-2024-43981

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 3

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 50.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 50.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical ayecode CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.07

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 8
4.0-6.9 2
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS ayecode CVEs

These are the five CVEs with the highest CVSS scores for ayecode, sorted by severity first and recency.

All CVEs for ayecode

CVE-2024-43981 ayecode vulnerability CVSS: 0 01 Nov 2024, 15:15 UTC

Missing Authorization vulnerability in AyeCode – WP Business Directory Plugins GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GeoDirectory: from n/a through 2.3.70.

CVE-2024-43973 ayecode vulnerability CVSS: 0 01 Nov 2024, 15:15 UTC

Missing Authorization vulnerability in AyeCode Ltd GetPaid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GetPaid: from n/a through 2.8.11.

CVE-2024-6265 ayecode vulnerability CVSS: 0 29 Jun 2024, 05:15 UTC

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uwp_sort_by’ parameter in all versions up to, and including, 1.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2023-50845 ayecode vulnerability CVSS: 0 28 Dec 2023, 19:15 UTC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode - WordPress Business Directory Plugins GeoDirectory – WordPress Business Directory Plugin, or Classified Directory.This issue affects GeoDirectory – WordPress Business Directory Plugin, or Classified Directory: from n/a through 2.3.28.

CVE-2022-47442 ayecode vulnerability CVSS: 0 07 Nov 2023, 15:15 UTC

Improper Neutralization of Formula Elements in a CSV File vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a through 1.2.3.9.

CVE-2022-4775 ayecode vulnerability CVSS: 0 23 Jan 2023, 15:15 UTC

The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-29453 ayecode vulnerability CVSS: 4.3 15 Jun 2022, 16:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Google Maps API key update.

CVE-2022-0442 ayecode vulnerability CVSS: 4.0 07 Mar 2022, 09:15 UTC

The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.

CVE-2021-24720 ayecode vulnerability CVSS: 3.5 11 Oct 2021, 11:15 UTC

The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS).

CVE-2021-24369 ayecode vulnerability CVSS: 3.5 21 Jun 2021, 20:15 UTC

In the GetPaid WordPress plugin before 2.3.4, users with the contributor role and above can create a new Payment Form, however the Label and Help Text input fields were not getting sanitized properly. So it was possible to inject malicious content such as img tags, leading to a Stored Cross-Site Scripting issue which is triggered when the form will be edited, for example when an admin reviews it and could lead to privilege escalation.

CVE-2021-24361 ayecode vulnerability CVSS: 7.5 21 Jun 2021, 20:15 UTC

In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues.