CVE-2025-31044 HIGH

CVE-2025-31044: WordPress Premium SEO Pack <= 3.3.2 - SQL Injection Vulnerability

Vendor Aa-Team
Product Premium SEO Pack
Weakness CWE-89 · SQLi
Published January 5, 2026
Last update April 28, 2026

CVSS base score

8.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

What the vulnerability does

01Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Premium SEO Pack allows SQL Injection.This issue affects Premium SEO Pack: from n/a through 3.3.2.

Explanation of Vulnerability in Simple Terms

02Summary

Premium SEO Pack versions up to 3.3.2 contain a SQL injection vulnerability in a component requiring low-level authentication. An attacker with a user account can craft malicious input to read or modify database contents, potentially affecting other users' data. The vulnerability has a wide scope, meaning the impact extends beyond the vulnerable component itself.

What an attacker can do

03Attacker Capabilities

Read or modify database contents, including other users' data and site configuration.

Potential impact on your site

04Site Impact

Unauthorized access to sensitive database records; potential data theft or corruption affecting all site users.

Conditions required to exploit

05Prerequisites

Attacker must have a user account with low-level privileges on the site.

Key dates

06Disclosure timeline

January 5, 2026 CVE published
April 28, 2026 Record updated