CyberRota Analysis
AI-GeneratedThe 12 Step Meeting List WordPress plugin prior to version 3.19.17 is vulnerable to Stored Cross-Site Scripting due to inadequate sanitization and escaping of user-submitted values in its activity log. This flaw allows unauthenticated attackers to inject malicious scripts that could be executed in the context of high-privilege users, such as administrators, potentially compromising the site's integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.
Original NVD Description
The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as admin.