Vulnerabilities > Ayecode
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-01-23 | CVE-2022-4775 | Unspecified vulnerability in Ayecode Geodirectory The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | 5.4 |
2022-06-15 | CVE-2022-29453 | Unspecified vulnerability in Ayecode API KEY for Google Maps 1.2.1 Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Google Maps API key update. | 4.3 |
2022-03-07 | CVE-2022-0442 | Authorization Bypass Through User-Controlled Key vulnerability in Ayecode Userswp The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar. | 4.3 |
2021-10-11 | CVE-2021-24720 | Unspecified vulnerability in Ayecode Geodirectory The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS). | 5.4 |
2021-06-21 | CVE-2021-24361 | Unspecified vulnerability in Ayecode Location Manager In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues. | 9.8 |
2021-06-21 | CVE-2021-24369 | Unspecified vulnerability in Ayecode Getpaid In the GetPaid WordPress plugin before 2.3.4, users with the contributor role and above can create a new Payment Form, however the Label and Help Text input fields were not getting sanitized properly. | 5.4 |