Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

AA-Team — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting AA-Team. AI-powered Chinese analysis, POCs, and references for each vulnerability.

AA-Team operates as a specialized software development entity, primarily focusing on enterprise resource planning and industrial automation solutions. Their product portfolio has been associated with twenty-one recorded Common Vulnerabilities and Exposures, indicating a consistent pattern of security oversight in legacy codebases. The most prevalent vulnerability classes include remote code execution and cross-site scripting, which often stem from insufficient input validation and improper session management practices. Privilege escalation flaws have also been documented, allowing unauthorized users to gain administrative access to critical system components. While no single catastrophic incident has publicly defined their security history, the cumulative nature of these CVEs suggests systemic weaknesses in their secure development lifecycle. Recent patches have addressed several critical remote execution vectors, yet the recurring nature of these issues highlights ongoing challenges in maintaining robust application security standards across their diverse software offerings.

CVE ID Title CVSS Severity Published
CVE-2025-49403 WordPress Premium Age Verification / Restriction for WordPress Plugin <= 3.0.2 - Arbitrary File Download Vulnerability — Premium Age Verification / Restriction for WordPress CWE-98 7.5 High 2026-06-17
CVE-2025-14361 WordPress Woocommerce Envato Affiliates plugin <= 1.2.1 - Settings Change vulnerability — Woocommerce Envato Affiliates CWE-862 7.1 High 2026-05-26
CVE-2026-27040 WordPress WZone plugin <= 14.0.31 - Arbitrary File Deletion vulnerability — WZone CWE-22 8.8 High 2026-03-25
CVE-2026-27039 WordPress WZone plugin <= 14.0.31 - SQL Injection vulnerability — WZone CWE-89 8.5 High 2026-03-25
CVE-2026-25473 WordPress WZone plugin <= 14.0.31 - Broken Access Control vulnerability — WZone CWE-862 5.4 Medium 2026-02-19
CVE-2026-22359 WordPress Wordpress Movies Bulk Importer plugin <= 1.0 - Cross Site Request Forgery (CSRF) vulnerability — Wordpress Movies Bulk Importer CWE-352 4.3 Medium 2026-01-22
CVE-2026-22360 WordPress SearchAzon plugin <= 1.4 - Cross Site Request Forgery (CSRF) vulnerability — SearchAzon CWE-352 4.3 Medium 2026-01-22
CVE-2025-30631 Reflected Cross Site Scripting (XSS) vulnerability in AA-Team WordPress plugins — Woocommerce Sales Funnel Builder CWE-79 7.1 High 2026-01-06
CVE-2025-29004 Privilege Escalation Vulnerability in AA-Team WordPress plugins — Premium Age Verification / Restriction for WordPress CWE-266 8.8 High 2026-01-06
CVE-2025-31044 WordPress Premium SEO Pack <= 3.3.2 - SQL Injection Vulnerability — Premium SEO Pack CWE-89 8.5 High 2026-01-05
CVE-2025-30633 WordPress Amazon Native Shopping Recommendations Plugin <= 1.3 - SQL Injection Vulnerability — Amazon Native Shopping Recommendations CWE-89 9.3 Critical 2026-01-05
CVE-2025-30628 WordPress Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) plugin <= 1.2 - SQL Injection Vulnerability — Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) CWE-89 8.5 High 2025-12-31
CVE-2025-28973 WordPress Pro Bulk Watermark Plugin for WordPress <= 2.0 - Path Traversal Vulnerability — Pro Bulk Watermark Plugin for WordPress CWE-35 6.5 Medium 2025-12-31
CVE-2025-53297 WordPress Woocommerce Envato Affiliates plugin <= 1.2.1 - Cross Site Scripting (XSS) vulnerability — Woocommerce Envato Affiliates CWE-79 7.1 High 2025-10-22
CVE-2025-4956 WordPress Pro Bulk Watermark Plugin for WordPress Theme <= 2.0 - Path Traversal Vulnerability — Pro Bulk Watermark Plugin for WordPress CWE-35 4.3 Medium 2025-08-30
CVE-2025-7401 Premium Age Verification / Restriction for WordPress <= 3.0.2 - Unauthenticated Arbitrary File Read and Write via remote_tunnel.php — Premium Age Verification / Restriction for WordPress CWE-798 9.8 Critical 2025-07-11
CVE-2024-33545 WordPress WZone plugin <= 14.0.10 - Unauthenticated Broken Access Control vulnerability — WZone CWE-862 5.3 Medium 2024-06-09
CVE-2024-33547 WordPress WZone plugin <= 14.0.10 - Site Wide Broken Access Control vulnerability — WZone CWE-862 8.3 High 2024-06-09
CVE-2024-33549 WordPress WZone plugin <= 14.0.10 - Privilege Escalation vulnerability — WZone CWE-269 8.8 High 2024-05-17
CVE-2024-33544 WordPress WZone plugin <= 14.0.10 - Unauthenticated SQL Injection vulnerability — WZone CWE-89 9.3 Critical 2024-04-29
CVE-2024-33546 WordPress WZone plugin <= 14.0.10 - Arbitrary SQL Update Execution vulnerability — WZone CWE-89 9.6 Critical 2024-04-29
CVE-2024-33548 WordPress WZone plugin <= 14.0.10 - Reflected Cross Site Scripting (XSS) vulnerability — WZone CWE-79 7.1 High 2024-04-29
CVE-2022-27628 WordPress WZone – Lite Version Plugin <= 3.1 Lite is vulnerable to Cross Site Request Forgery (CSRF) — WZone – Lite Version CWE-352 4.7 Medium 2023-02-06

This page lists every published CVE security advisory associated with AA-Team. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.