Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Affiliates Addon for WPBakery Pag...
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) allows SQL Injection
AI Analyst Comment
Remediation
Apply vendor patches immediately. Review database access controls and enable query logging.
Description Summary:
A SQL injection vulnerability in the AA-Team Amazon Affiliates Addon for WPBakery Page Builder allows authenticated attackers to execute unauthorized database queries.
Executive Summary:
A critical SQL injection vulnerability in the Amazon Affiliates Addon for WPBakery Page Builder allows authenticated attackers to compromise database confidentiality and integrity.
Vulnerability Details
CVE-ID: CVE-2025-30628
Affected Software: AA-Team Amazon Affiliates Addon for WPBakery Page Builder
Affected Versions: n/a through 1.2
Vulnerability: This vulnerability is a SQL injection (CWE-89) flaw caused by improper neutralization of special elements in SQL commands. The CVSS vector (PR:L) indicates that an attacker must possess low-level privileges to successfully trigger the vulnerability.
Business Impact
The ability to perform SQL injection poses a significant risk to data confidentiality, as attackers may be able to extract sensitive information from the underlying WordPress database. Given the CVSS score of 8.5, this high-severity flaw could lead to unauthorized data exposure or partial service disruption, potentially violating data privacy regulations and damaging organizational reputation.
Remediation Plan
Immediate Action: Since no official patch is currently confirmed, administrators should immediately disable or uninstall the Amazon Affiliates Addon until a secure version is released by the vendor.
Proactive Monitoring: Security teams should review database query logs for anomalous patterns, such as unexpected syntax or large data exports, which may indicate active exploitation attempts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets designed to detect and block common SQL injection patterns to provide a layer of virtual patching.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of January 2, 2026, there is no public information indicating active exploitation or a published proof-of-concept for this vulnerability. While exploitation is not currently confirmed, SQL injection flaws are inherently dangerous and often targeted by automated scanners.
Analyst Recommendation
Due to the severity of this vulnerability and the potential for unauthorized database access, users of the Amazon Affiliates Addon must prioritize removing the plugin from their production environments. Until a vendor patch is verified and applied, the risk of data compromise remains elevated for any site using versions 1.2 or earlier.