Impact
The 12 Step Meeting List WordPress plugin lacks proper authorization controls, enabling an authenticated user to delete any content managed by the plugin. Due to the missing access control (CWE-862), an attacker could remove posts, pages, or custom entries, leading to loss of information integrity and potential disruption of business operations.
Affected Systems
AA Web Servant’s 12 Step Meeting List plugin, versions up to and including 3.16.5, is affected. All product releases from the earliest available version through 3.16.5 contain the flaw and lack the necessary fix.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low current likelihood of exploitation, and the vulnerability is not recorded in the CISA KEV catalog. While the CVE does not explicitly state the attack vector, it is inferred that the flaw can be exploited remotely via the web interface by any logged‑in user due to the missing authorization checks, although the precise conditions are not detailed.
OpenCVE Enrichment
EUVD