Impact
The 12 Step Meeting List plugin for WordPress has an unauthenticated Cross‑Site Scripting flaw in versions up to 3.19.16. A malicious actor can supply crafted input that is rendered without proper escaping, enabling the injection of arbitrary JavaScript. If exploited, the injected script runs under the context of site visitors, potentially stealing session cookies, defacing the site, or redirecting users to phishing pages. The vulnerability arises from insufficient input validation, as identified by CWE‑79.
Affected Systems
WordPress installations that use the Code for Recovery 12 Step Meeting List plugin version 3.19.16 or earlier. These versions are listed as vulnerable and not patched.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity of the flaw. EPSS is not available, and the issue is not listed in CISA’s KEV catalog, suggesting no widespread exploitation observed. The likely attack vector is any web user who visits a page generated by the plugin; the attacker does not need authentication. Consequently, the risk is to confidentiality and integrity of the site’s visitors, while availability is less directly impacted.
OpenCVE Enrichment