AA-Team Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with AA-Team products.
Products
- WZone9 vulnerabilities
- Premium Age Verification / Restriction for WordPress3 vulnerabilities
- Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer)2 vulnerabilities
- Pro Bulk Watermark Plugin for WordPress2 vulnerabilities
- Woocommerce Envato Affiliates2 vulnerabilities
- Amazon Native Shopping Recommendations1 vulnerability
- Premium SEO Pack1 vulnerability
- Responsive Coming Soon Landing Page / Holding Page for WordPress1 vulnerability
- SearchAzon1 vulnerability
- Woocommerce Sales Funnel Builder1 vulnerability
- Wordpress Movies Bulk Importer1 vulnerability
- WZone – Lite Version1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-49403HIGH | WordPress Premium Age Verification / Restriction for WordPress Plugin <= 3.0.2 - Arbitrary File Download VulnerabilityUnauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions. CWE-98Jun 17, 2026 | CVSS7.5v3.1 | EPSS0.304% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-14361HIGH | WordPress Woocommerce Envato Affiliates plugin <= 1.2.1 - Settings Change vulnerabilityMissing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Woocommerce Envato Affiliates: from n/a through 1.2.1. CWE-862May 26, 2026 | CVSS7.1v3.1 | EPSS0.248% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-27040HIGH | WordPress WZone plugin <= 14.0.31 - Arbitrary File Deletion vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AA-Team WZone woozone allows Path Traversal.This issue affects WZone: from n/a through <= 14.0.31. CWE-22Mar 25, 2026 | CVSS8.8v3.1 | EPSS0.382% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-27039HIGH | WordPress WZone plugin <= 14.0.31 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone woozone allows Blind SQL Injection.This issue affects WZone: from n/a through <= 14.0.31. CWE-89Mar 25, 2026 | CVSS8.5v3.1 | EPSS0.253% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25473MEDIUM | WordPress WZone plugin <= 14.0.31 - Broken Access Control vulnerabilityMissing Authorization vulnerability in AA-Team WZone woozone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WZone: from n/a through <= 14.0.31. CWE-862Feb 19, 2026 | CVSS5.4v3.1 | EPSS0.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22359MEDIUM | WordPress Wordpress Movies Bulk Importer plugin <= 1.0 - Cross Site Request Forgery (CSRF) vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in AA-Team Wordpress Movies Bulk Importer movies importer allows Cross Site Request Forgery.This issue affects Wordpress Movies Bulk Importer: from n/a through <= 1.0. CWE-352Jan 22, 2026 | CVSS4.3v3.1 | EPSS0.133% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22360MEDIUM | WordPress SearchAzon plugin <= 1.4 - Cross Site Request Forgery (CSRF) vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in AA-Team SearchAzon searchazon allows Cross Site Request Forgery.This issue affects SearchAzon: from n/a through <= 1.4. CWE-352Jan 22, 2026 | CVSS4.3v3.1 | EPSS0.107% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-30631HIGH | Reflected Cross Site Scripting (XSS) vulnerability in AA-Team WordPress pluginsImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerce Sales Funnel Builder, AA-Team Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) allows Reflected XSS.This issue affects Woocommerce Sales Funnel Builder: from n/a through 1.1; Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer): from n/a through 1.2. CWE-79Jan 6, 2026 | CVSS7.1v3.1 | EPSS0.153% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-29004HIGH | Privilege Escalation Vulnerability in AA-Team WordPress pluginsIncorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through 3.0.2; Responsive Coming Soon Landing Page / Holding Page for WordPress: from n/a through 3.0. CWE-266Jan 6, 2026 | CVSS8.8v3.1 | EPSS0.264% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-31044HIGH | WordPress Premium SEO Pack <= 3.3.2 - SQL Injection VulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Premium SEO Pack allows SQL Injection.This issue affects Premium SEO Pack: from n/a through 3.3.2. CWE-89Jan 5, 2026 | CVSS8.5v3.1 | EPSS0.219% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-30633CRITICAL | WordPress Amazon Native Shopping Recommendations Plugin <= 1.3 - SQL Injection VulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Native Shopping Recommendations allows SQL Injection.This issue affects Amazon Native Shopping Recommendations: from n/a through 1.3. CWE-89Jan 5, 2026 | CVSS9.3v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-30628HIGH | WordPress Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) plugin <= 1.2 - SQL Injection VulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) allows SQL Injection.This issue affects Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer): from n/a through 1.2. CWE-89Dec 31, 2025 | CVSS8.5v3.1 | EPSS0.219% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-28973MEDIUM | WordPress Pro Bulk Watermark Plugin for WordPress <= 2.0 - Path Traversal VulnerabilityPath Traversal: '.../...//' vulnerability in AA-Team Pro Bulk Watermark Plugin for WordPress pro-watermark allows Path Traversal.This issue affects Pro Bulk Watermark Plugin for WordPress: from n/a through <= 2.0. CWE-35Dec 31, 2025 | CVSS6.5v3.1 | EPSS0.307% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-53297HIGH | WordPress Woocommerce Envato Affiliates plugin <= 1.2.1 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerce Envato Affiliates wooenvato allows Reflected XSS.This issue affects Woocommerce Envato Affiliates: from n/a through <= 1.2.1. CWE-79Oct 22, 2025 | CVSS7.1v3.1 | EPSS0.219% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-4956MEDIUM | WordPress Pro Bulk Watermark Plugin for WordPress Theme <= 2.0 - Path Traversal VulnerabilityPath Traversal: '.../...//' vulnerability in AA-Team Pro Bulk Watermark Plugin for WordPress allows Path Traversal.This issue affects Pro Bulk Watermark Plugin for WordPress: from n/a through 2.0. CWE-35Aug 30, 2025 | CVSS4.3v3.1 | EPSS0.295% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-7401CRITICAL | Premium Age Verification / Restriction for WordPress <= 3.0.2 - Unauthenticated Arbitrary File Read and Write via remote_tunnel.phpThe Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to read from or write to arbitrary files on the affected site's server which may make the exposure of sensitive information or remote code execution possible. CWE-798Jul 11, 2025 | CVSS9.8v3.1 | EPSS0.546% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33545MEDIUM | WordPress WZone plugin <= 14.0.10 - Unauthenticated Broken Access Control vulnerabilityMissing Authorization vulnerability in AA-Team WZone.This issue affects WZone: from n/a through 14.0.10. CWE-862Jun 9, 2024 | CVSS5.3v3.1 | EPSS0.365% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33547HIGH | WordPress WZone plugin <= 14.0.10 - Site Wide Broken Access Control vulnerabilityMissing Authorization vulnerability in AA-Team WZone.This issue affects WZone: from n/a through 14.0.10. CWE-862Jun 9, 2024 | CVSS8.3v3.1 | EPSS0.387% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33549HIGH | WordPress WZone plugin <= 14.0.10 - Privilege Escalation vulnerabilityImproper Privilege Management vulnerability in AA-Team WZone allows Privilege Escalation.This issue affects WZone: from n/a through 14.0.10. CWE-269May 17, 2024 | CVSS8.8v3.1 | EPSS0.512% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33544CRITICAL | WordPress WZone plugin <= 14.0.10 - Unauthenticated SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10. CWE-89Apr 29, 2024 | CVSS9.3v3.1 | EPSS0.629% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33546CRITICAL | WordPress WZone plugin <= 14.0.10 - Arbitrary SQL Update Execution vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10. CWE-89Apr 29, 2024 | CVSS9.6v3.1 | EPSS0.529% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33548HIGH | WordPress WZone plugin <= 14.0.10 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team WZone allows Reflected XSS.This issue affects WZone: from n/a through 14.0.10. CWE-79Apr 29, 2024 | CVSS7.1v3.1 | EPSS0.375% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-27628MEDIUM | WordPress WZone – Lite Version Plugin <= 3.1 Lite is vulnerable to Cross Site Request Forgery (CSRF)Cross-Site Request Forgery (CSRF) vulnerability in AA-Team WZone – Lite Version plugin 3.1 Lite versions. CWE-352Feb 6, 2023 | CVSS4.7v3.1 | EPSS0.234% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |