CVE-2026-78333
Received Received - Intake

Stored XSS in 12 Step Meeting List WordPress Plugin

Vulnerability report for CVE-2026-78333, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: WPScan

Description

The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as admin.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
12_step_meeting_list plugin to 3.19.17 (exc)
12_step_meeting_list plugin to 3.19.16 (inc)
12_step_meeting_list 12_step_meeting_list to 3.19.17 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored Cross-Site Scripting (XSS) vulnerability in the 12 Step Meeting List WordPress plugin affecting versions 3.17 to 3.19.16. It allows unauthenticated users to submit malicious input that is not properly sanitized or escaped before being stored in the plugin's activity log and displayed in an admin area page. This could enable attackers to inject and execute malicious scripts in the browsers of high-privilege users like administrators.

Detection Guidance

Check if your WordPress site uses the 12 Step Meeting List plugin versions 3.17 to 3.19.16. Inspect the plugin's activity log for suspicious entries containing script tags or unusual input. Review admin area pages for unexpected content execution.

Impact Analysis

If you are an administrator or high-privilege user of a WordPress site using the vulnerable plugin versions, an attacker could exploit this to run malicious scripts in your browser. This may lead to unauthorized actions on your site, theft of session cookies, or further compromise of your WordPress installation. Regular users could also be affected if the injected scripts target them.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR (data protection) or HIPAA (health information privacy). If exploited, it could result in unauthorized data exposure or modification, triggering reporting obligations and potential fines under these regulations.

Mitigation Strategies

Update the 12 Step Meeting List plugin to version 3.19.17 or later immediately. If updating is not possible, consider disabling the plugin until an update is applied. Monitor admin area pages for signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78333. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart