Cross-Site Scripting Vulnerability in AA-Team WooCommerce Sales Funnel Builder and Amazon Affiliates Addon
CVE-2025-30631
7.1HIGH
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 6 January 2026
What is CVE-2025-30631?
The AA-Team WooCommerce Sales Funnel Builder and the Amazon Affiliates Addon for WPBakery Page Builder have a vulnerability that allows for reflected cross-site scripting (XSS) due to improper input neutralization during web page generation. This security concern can lead to unauthorized access or manipulation of a user's session, resulting in potential exploitation by malicious actors. Users are urged to update their products to the latest versions to mitigate the risk of exploitation.
Affected Version(s)
Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) <= 1.2
Woocommerce Sales Funnel Builder <= 1.1
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program