Sceawere

Vulnerability Detail

CVE-2026-66584UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in 12 Step Meeting List

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Code for Recovery
Product
12 Step Meeting List
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-24T12:16:52.543Z",
  "pubdate": "2026-08-24T12:16:52.543Z",
  "executiveSummary": "An unauthenticated Cross-Site Scripting (XSS) vulnerability has been identified in the 12 Step Meeting List plugin affecting versions 3.19.16 and prior. This security flaw enables remote attackers to inject malicious client-side scripts, typically JavaScript, into web pages rendered to unsuspecting users visiting the affected WordPress sites. The primary impact of this vulnerability includes session hijacking, credential theft, defacement of the web application interface, and redirection of users to malicious external domains. Because the vulnerability is unauthenticated, threat actors require no prior access, privileges, or user interaction beyond tricking a victim into executing the payload or visiting a crafted URL, thereby significantly lowering the barrier to exploitation. The risk implication is severe for organizations utilizing the vulnerable software, as compromised user sessions can lead to administrative privilege escalation depending on the victim's permission level. Immediate remediation is necessary to prevent arbitrary code execution within the context of the user's browser session, safeguarding application integrity and user trust.",
  "technicalDetails": "The identified vulnerability stems from improper neutralization of user-supplied input before rendering it back to the client, a classic root cause for Cross-Site Scripting (XSS) flaws. Specifically, within the vulnerable versions of the 12 Step Meeting List plugin (<= 3.19.16), HTTP request parameters or stored database fields containing malicious markup are improperly sanitized, escaped, or validated prior to output generation. The attack vector is network-based and exposed over standard web protocols (HTTP/HTTPS), allowing unauthenticated remote threat actors to craft malicious payloads embedded within URL parameters or input fields. The attack flow begins when an attacker crafts a malicious HTTP request containing executable JavaScript or HTML payloads directed at the vulnerable endpoints of the 12 Step Meeting List application. Due to the absence of robust output encoding mechanisms within the rendering functions of the vulnerable component, the application incorporates the unvalidated input directly into the Document Object Model (DOM) of the HTTP response. When a victim's browser parses the server response, the malicious script executes within the security context of the victim's session, bypassing standard same-origin policy constraints regarding the vulnerable domain. Post-exploitation impact encompasses the complete compromise of the user's browser session, enabling the extraction of sensitive session cookies, authorization tokens, and personal identifiable information (PII). Furthermore, the attacker can leverage the executing script to perform unauthorized actions on behalf of the authenticated user, modify webpage content to capture credentials via phishing overlays, or pivot further into the internal web application architecture. No authentication or privilege requirements are mandated to deliver the payload, exposing the application to broad-scale automated scanning and exploitation campaigns across the internet."
}
CVE-2026-66584: Unauthenticated XSS in 12 Step Meeting List (HIGH Severity, CVSS: 7.1) - Sceawere