SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-78333

HIGH · CVSS 8.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The 12 Step Meeting List WordPress plugin prior to version 3.19.17 is vulnerable to Stored Cross-Site Scripting due to inadequate sanitization and escaping of user-submitted values in its activity log. This flaw allows unauthenticated attackers to inject malicious scripts that could be executed in the context of high-privilege users, such as administrators, potentially compromising the site's integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-78333
Severity
HIGH
CVSS
8.8
EPSS
0.28%
WordPress

Original NVD Description

The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as admin.