Description
Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.
Published: 2026-08-24
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The 12 Step Meeting List plugin for WordPress has an unauthenticated Cross‑Site Scripting flaw in versions up to 3.19.16. A malicious actor can supply crafted input that is rendered without proper escaping, enabling the injection of arbitrary JavaScript. If exploited, the injected script runs under the context of site visitors, potentially stealing session cookies, defacing the site, or redirecting users to phishing pages. The vulnerability arises from insufficient input validation, as identified by CWE‑79.

Affected Systems

WordPress installations that use the Code for Recovery 12 Step Meeting List plugin version 3.19.16 or earlier. These versions are listed as vulnerable and not patched.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity of the flaw. EPSS is not available, and the issue is not listed in CISA’s KEV catalog, suggesting no widespread exploitation observed. The likely attack vector is any web user who visits a page generated by the plugin; the attacker does not need authentication. Consequently, the risk is to confidentiality and integrity of the site’s visitors, while availability is less directly impacted.

Generated by OpenCVE AI on August 24, 2026 at 12:24 UTC.

Remediation

Vendor Solution

Update the WordPress 12 Step Meeting List Plugin to the latest available version (at least 3.19.17).


OpenCVE Recommended Actions

  • Update the 12 Step Meeting List plugin to version 3.19.17 or later.
  • If an immediate update is not feasible, temporarily deactivate or remove the plugin to eliminate the vulnerability.
  • Review the plugin’s configuration and ensure that any user‑supplied data is strictly validated and escaped to prevent future injection issues.

Generated by OpenCVE AI on August 24, 2026 at 12:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.
Title WordPress 12 Step Meeting List plugin <= 3.19.16 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-24T12:51:11.006Z

Reserved: 2026-07-27T14:00:04.572Z

Link: CVE-2026-66584

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T12:16:52.543

Modified: 2026-08-24T12:16:52.543

Link: CVE-2026-66584

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T12:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')