๐Ÿ” CVE Alert

CVE-2026-78333

UNKNOWN 0.0

12 Step Meeting List 3.17 - 3.19.16 - Unauthenticated Stored XSS via Geocode Event Log

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as admin.

Vendor unknown
Product 12 step meeting list
Published Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for unknown 12 step meeting list

Be the first to know when new unknown vulnerabilities affecting unknown 12 step meeting list are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / 12 Step Meeting List
3.17 < 3.19.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/27de9242-d60e-42e8-a3a5-e355bfc00393/

Credits

Huseyn WPScan