Junglewise Threat Intelligence

CVE-2025-30628: AA-Team Amazon Affiliates Addon for WPBakery SQL injection

CVE-2025-30628 · Severity: high · CVSS 8.5 · Published 2025-12-31

Executive brief

A WordPress plugin used to display Amazon affiliate product recommendations within page builder layouts contains a SQL injection vulnerability. An attacker with a subscriber account can craft malicious requests to read, modify, or delete the website's entire database, including user credentials and sensitive business data.

Technical details

The Amazon Affiliates Addon for WPBakery Page Builder (versions ≤1.2) fails to properly sanitize user input before using it in SQL queries, allowing SQL injection attacks. The vulnerability requires subscriber-level privileges to exploit and is reachable over the network through the plugin's interface. An authenticated attacker can execute arbitrary SQL commands to compromise database integrity, extract sensitive data, or modify website content. No official patch is currently available; Patchstack has issued a mitigation rule pending a vendor fix.

Affected products

  • AA-Team Amazon Affiliates Addon for WPBakery Page Builder through 1.2

Timeline

  • 2025-07-07: disclosed: Published by Patchstack
  • 2025-06-02: other: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)

References