Impact
The AA‑Team Premium SEO Pack plugin contains an injection flaw where input is incorporated into an SQL command without proper neutralization of special elements, creating a classic SQL Injection vulnerability. This weakness, classified as CWE‑89, would allow an attacker to read, modify, or delete database records, thereby undermining the confidentiality, integrity, and availability of the site’s data.
Affected Systems
All WordPress installations that have the Premium SEO Pack plugin at version 3.3.2 or earlier are affected. No other WordPress core components or plugins are explicitly listed in the advisory, so the vulnerability is confined to sites that include this plugin and have it enabled.
Risk and Exploitability
The CVSS score of 8.5 signals a high severity level, yet the EPSS score of less than 1% suggests that exploitation has been observed only at a very low frequency. Because the vulnerability is not listed in the CISA KEV catalog, it has not yet been confirmed as a widely exploited flaw. The likely attack vector is inferred to be the plugin’s HTTP request handling, where an attacker could craft specially formed requests that are passed straight into database queries; a successful attack would grant the attacker direct access to the WordPress database.
OpenCVE Enrichment