CVE-2025-30631: Aa-Team Amazon Affiliates Addon For Wpbakery Page Builder Formerly Visual Composer
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerce Sales Funnel Builder, AA-Team Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) allows Reflected XSS.This issue affects Woocommerce Sales Funnel Builder: from n/a through 1.1; Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer): from n/a through 1.2.
Affected products
- Aa-Team Amazon Affiliates Addon For Wpbakery Page Builder Formerly Visual Composer: up to and including 1.2
- Aa-Team Woocommerce Sales Funnel Builder: up to and including 1.1
Published 2026-01-06. Last modified 2026-06-17.