Beveiligingsadvies

CVE-2026-78333

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-27 06:00:20
Laatst bijgewerkt 2026-08-27 14:23:45
Toegewezen door WPScan
CVSS-score 8.8
Status PUBLISHED

Beschrijving

The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as admin.