CVE-2026-66584: WordPress 12 Step Meeting List plugin <= 3.19.16 - Cross Site Scripting (XSS) vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.
Affected Software
1 affected component
WordPress 12 Step Meeting List<=3.19.16
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress 12 Step Meeting List pluginto a version that resolves this vulnerability.Fixed in 3.19.17
Event History
Aug 24, 2026
CVE Published
via MITRE·11:39 AM
Data Sourced
via MITRE·11:39 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
No authentication is required. Exploitation does require user interaction, indicating that an attacker must persuade a user to interact with crafted content.
2
Which installations are affected?
WordPress sites using the 12 Step Meeting List plugin version 3.19.16 or earlier are affected according to the available data.
3
What security impact can exploitation have?
The issue is rated high severity with a CVSS score of 7.1. Successful exploitation can affect confidentiality, integrity, and availability at low impact, with scope changed.