Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Stored XSS.This issue affects 12 Step Meeting List: from n/a through <= 3.18.3.
Published: 2025-08-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

AA Web Servant 12 Step Meeting List is vulnerable to a stored cross‑site scripting flaw because user input is not properly neutralized when generating web pages. An attacker who can inject data into the plugin’s storage can later cause arbitrary malicious scripts to execute in the browsers of any visitors who view affected pages. The weakness is a classic input validation flaw (CWE‑79) that compromises confidentiality, integrity and availability of user data and can be leveraged for credential theft, defacement or other malicious actions.

Affected Systems

This issue applies to the WordPress plugin 12 Step Meeting List from AA Web Servant, versions 3.18.3 and earlier. Sites running any of those releases are potentially affected. Since the vulnerability persists across all earlier releases, any host that has never upgraded past 3.18.3 is at risk.

Risk and Exploitability

The CVSS base score of 6.5 indicates a moderate impact, while the EPSS score being below 1% shows low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Because the flaw is stored and leveraged through website content, an attacker can inject JavaScript that executes only when users load problematic pages, making it a typical stored XSS attack via data entry into the plugin, with no special privileges required beyond the ability to submit or edit content that the plugin stores.

Generated by OpenCVE AI on April 30, 2026 at 16:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest version of the 12 Step Meeting List plugin (≥ 3.18.4) to eliminate the stored XSS flaw.
  • Sanitize or remove any existing malicious content stored by the plugin and review past entries for injected scripts.
  • Restrict content submission to administrators or disable the plugin until the patch is applied.

Generated by OpenCVE AI on April 30, 2026 at 16:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-24905 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA Web Servant 12 Step Meeting List allows Stored XSS. This issue affects 12 Step Meeting List: from n/a through 3.18.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA Web Servant 12 Step Meeting List allows Stored XSS. This issue affects 12 Step Meeting List: from n/a through 3.18.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Stored XSS.This issue affects 12 Step Meeting List: from n/a through <= 3.18.3.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 15 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Aa Web Servant
Aa Web Servant 12 Step Meeting List
Wordpress
Wordpress wordpress
Vendors & Products Aa Web Servant
Aa Web Servant 12 Step Meeting List
Wordpress
Wordpress wordpress

Thu, 14 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA Web Servant 12 Step Meeting List allows Stored XSS. This issue affects 12 Step Meeting List: from n/a through 3.18.3.
Title WordPress 12 Step Meeting List Plugin <= 3.18.3 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Aa Web Servant 12 Step Meeting List
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:30.163Z

Reserved: 2025-07-16T08:52:18.650Z

Link: CVE-2025-54054

cve-icon Vulnrichment

Updated: 2025-08-14T19:59:33.500Z

cve-icon NVD

Status : Deferred

Published: 2025-08-14T19:15:37.043

Modified: 2026-04-23T15:32:46.870

Link: CVE-2025-54054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T16:15:06Z

Weaknesses