AA-Team Vulnerabilities and Affected Products
Vulnerabilities associated with WZone.
Products
Clear product- WZone9 vulnerabilities
- Premium Age Verification / Restriction for WordPress3 vulnerabilities
- Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer)2 vulnerabilities
- Pro Bulk Watermark Plugin for WordPress2 vulnerabilities
- Woocommerce Envato Affiliates2 vulnerabilities
- Amazon Native Shopping Recommendations1 vulnerability
- Premium SEO Pack1 vulnerability
- Responsive Coming Soon Landing Page / Holding Page for WordPress1 vulnerability
- SearchAzon1 vulnerability
- Woocommerce Sales Funnel Builder1 vulnerability
- Wordpress Movies Bulk Importer1 vulnerability
- WZone – Lite Version1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-27040HIGH | WordPress WZone plugin <= 14.0.31 - Arbitrary File Deletion vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AA-Team WZone woozone allows Path Traversal.This issue affects WZone: from n/a through <= 14.0.31. CWE-22Mar 25, 2026 | CVSS8.8v3.1 | EPSS0.382% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-27039HIGH | WordPress WZone plugin <= 14.0.31 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone woozone allows Blind SQL Injection.This issue affects WZone: from n/a through <= 14.0.31. CWE-89Mar 25, 2026 | CVSS8.5v3.1 | EPSS0.253% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25473MEDIUM | WordPress WZone plugin <= 14.0.31 - Broken Access Control vulnerabilityMissing Authorization vulnerability in AA-Team WZone woozone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WZone: from n/a through <= 14.0.31. CWE-862Feb 19, 2026 | CVSS5.4v3.1 | EPSS0.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33545MEDIUM | WordPress WZone plugin <= 14.0.10 - Unauthenticated Broken Access Control vulnerabilityMissing Authorization vulnerability in AA-Team WZone.This issue affects WZone: from n/a through 14.0.10. CWE-862Jun 9, 2024 | CVSS5.3v3.1 | EPSS0.365% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33547HIGH | WordPress WZone plugin <= 14.0.10 - Site Wide Broken Access Control vulnerabilityMissing Authorization vulnerability in AA-Team WZone.This issue affects WZone: from n/a through 14.0.10. CWE-862Jun 9, 2024 | CVSS8.3v3.1 | EPSS0.387% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33549HIGH | WordPress WZone plugin <= 14.0.10 - Privilege Escalation vulnerabilityImproper Privilege Management vulnerability in AA-Team WZone allows Privilege Escalation.This issue affects WZone: from n/a through 14.0.10. CWE-269May 17, 2024 | CVSS8.8v3.1 | EPSS0.512% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33544CRITICAL | WordPress WZone plugin <= 14.0.10 - Unauthenticated SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10. CWE-89Apr 29, 2024 | CVSS9.3v3.1 | EPSS0.629% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33546CRITICAL | WordPress WZone plugin <= 14.0.10 - Arbitrary SQL Update Execution vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10. CWE-89Apr 29, 2024 | CVSS9.6v3.1 | EPSS0.529% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33548HIGH | WordPress WZone plugin <= 14.0.10 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team WZone allows Reflected XSS.This issue affects WZone: from n/a through 14.0.10. CWE-79Apr 29, 2024 | CVSS7.1v3.1 | EPSS0.375% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |