12 Step Meeting List <= 3.19.16 - Unauthenticated Stored Cross-Site Scripting
high
The 12 Step Meeting List plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.19.16. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wh...
- CVSS:
- 7.2
- Affected:
- up to 3.19.16
- Fixed in:
- 3.19.17
- Disclosed:
- Aug 20, 2026
CVE-2026-66584 on NVD →
12 Step Meeting List <= 3.19.9 - Unauthenticated Information Exposure
medium
The 12 Step Meeting List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.19.9. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 3.19.9
- Fixed in:
- 3.19.10
- Disclosed:
- Mar 22, 2026
CVE-2026-39570 on NVD →
12 Step Meeting List <= 3.19.9 - Missing Authorization
medium
The 12 Step Meeting List plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.19.9. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.19.9
- Fixed in:
- 3.19.10
- Disclosed:
- Mar 22, 2026
CVE-2026-39569 on NVD →
12 Step Meeting List <= 3.18.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The 12 Step Meeting List plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...
- CVSS:
- 6.4
- Affected:
- up to 3.18.3
- Fixed in:
- 3.18.4
- Disclosed:
- Aug 14, 2025
CVE-2025-54054 on NVD →
12 Step Meeting List [12-step-meeting-list] < 3.18.4
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA Web Servant 12 Step Meeting List allows Stored XSS. This issue affects 12 Step Meeting List: from n/a through 3.18.3.
- Affected:
- up to 3.18.4
- Fixed in:
- 3.18.4
- Disclosed:
- Aug 14, 2025
CVE-2025-54054 on NVD →
12 Step Meeting List [12-step-meeting-list] < 3.16.6
unknown
[en] Missing Authorization vulnerability in AA Web Servant 12 Step Meeting List allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects 12 Step Meeting List: from n/a through 3.16.5.
- Affected:
- up to 3.16.6
- Fixed in:
- 3.16.6
- Disclosed:
- Apr 17, 2025
CVE-2025-24583 on NVD →
12 Step Meeting List <= 3.16.5 - Unauthenticated Sensitive Information Exposure
medium
The 12 Step Meeting List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.16.5. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 3.16.5
- Fixed in:
- 3.16.6
- Disclosed:
- Jan 24, 2025
CVE-2025-24582 on NVD →
12 Step Meeting List <= 3.16.5 - Missing Authorization to Authenticated (Contributor+) Arbitrary Content Deletion
medium
The 12 Step Meeting List plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wp_ajax_tsml_delete() function in all versions up to, and including, 3.16.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete all meetin...
- CVSS:
- 4.3
- Affected:
- up to 3.16.5
- Fixed in:
- 3.16.6
- Disclosed:
- Jan 24, 2025
CVE-2025-24580 on NVD →
12 Step Meeting List [12-step-meeting-list] < 3.16.6
unknown
[en] Insertion of Sensitive Information Into Sent Data vulnerability in Code for Recovery 12 Step Meeting List allows Retrieve Embedded Sensitive Data. This issue affects 12 Step Meeting List: from n/a through 3.16.5.
- Affected:
- up to 3.16.6
- Fixed in:
- 3.16.6
- Disclosed:
- Jan 24, 2025
CVE-2025-24582 on NVD →
12 Step Meeting List [12-step-meeting-list] < 3.16.6
unknown
[en] Missing Authorization vulnerability in Code for Recovery 12 Step Meeting List allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects 12 Step Meeting List: from n/a through 3.16.5.
- Affected:
- up to 3.16.6
- Fixed in:
- 3.16.6
- Disclosed:
- Jan 24, 2025
CVE-2025-24580 on NVD →
12 Step Meeting List <= 3.16.5 - Missing Authorization to Unauthenticated Settings Update
medium
The 12 Step Meeting List plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.16.5. This makes it possible for unauthenticated attackers to update plugin settings.
- CVSS:
- 5.3
- Affected:
- up to 3.16.5
- Fixed in:
- 3.16.6
- Disclosed:
- Dec 18, 2024
CVE-2025-24583 on NVD →
12 Step Meeting List [12-step-meeting-list] < 3.14.29
unknown
[en] Missing Authorization vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through 3.14.28.
- Affected:
- up to 3.14.29
- Fixed in:
- 3.14.29
- Disclosed:
- Jun 10, 2024
CVE-2024-22296 on NVD →
12 Step Meeting List [12-step-meeting-list] < 3.14.34
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Code for Recovery 12 Step Meeting List allows Reflected XSS.This issue affects 12 Step Meeting List: from n/a through 3.14.33.
- Affected:
- up to 3.14.34
- Fixed in:
- 3.14.34
- Disclosed:
- Jun 8, 2024
CVE-2024-35693 on NVD →
12 Step Meeting List <= 3.14.33 - Reflected Cross-Site Scripting
medium
The 12 Step Meeting List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.14.33 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...
- CVSS:
- 6.1
- Affected:
- up to 3.14.33
- Fixed in:
- 3.14.34
- Disclosed:
- Jun 6, 2024
CVE-2024-35693 on NVD →
12 Step Meeting List <= 3.14.28 - Missing Authorization
medium
The 12 Step Meeting List plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 3.14.28. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.14.28
- Fixed in:
- 3.14.29
- Disclosed:
- Jan 17, 2024
CVE-2024-22296 on NVD →
12 Step Meeting List [12-step-meeting-list] < 3.14.25
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through 3.14.24.
- Affected:
- up to 3.14.25
- Fixed in:
- 3.14.25
- Disclosed:
- Dec 7, 2023
CVE-2023-46641 on NVD →
12 Step Meeting List <= 3.14.24 - Authenticated (Contributor+) Server-Side Request Forgery
medium
The 12 Step Meeting List plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.14.24 via the tsml_add_data_source parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations origin...
- CVSS:
- 6.4
- Affected:
- up to 3.14.24
- Fixed in:
- 3.14.25
- Disclosed:
- Nov 27, 2023
CVE-2023-46641 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database