Executive brief
The 12 Step Meeting List plugin for WordPress, which helps organizations manage and display recovery meeting schedules, contains a security flaw in its access control settings. This vulnerability allows logged-in users with low-level permissions to bypass security restrictions and potentially access sensitive information they should not be able to see. Organizations using this plugin should update to the latest version to ensure their meeting data and administrative configurations remain secure.
Technical details
A missing authorization (CWE-862) vulnerability exists in the AA Web Servant 12 Step Meeting List plugin for WordPress in versions up to and including 3.19.9. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before granting access to certain functions or data. An attacker authenticated with 'Contributor' level privileges can exploit this over the network to gain unauthorized access to information (Impact: Confidentiality High). The issue is resolved in version 3.19.10.
Affected products
- AA Web Servant 12 Step Meeting List <= 3.19.9
Timeline
- 2026-02-20: other: Reported by Bao - BlueRock
- 2026-03-22: patched: Patch released in version 3.19.10
- 2026-04-08: disclosed: CVE published