Executive brief
The 12 Step Meeting List plugin for WordPress, which helps organizations manage and display recovery meeting schedules, contains a security flaw that exposes sensitive information. An unauthorized person could access data that is intended to be hidden or restricted, potentially compromising the privacy of meeting participants or site configurations. This issue can be resolved by updating the plugin to the latest version.
Technical details
A 'Insertion of Sensitive Information Into Sent Data' (CWE-201) vulnerability exists in the AA Web Servant 12 Step Meeting List plugin for WordPress in versions up to and including 3.19.9. The flaw allows an unauthenticated remote attacker to retrieve sensitive data that is inadvertently embedded in the data sent by the application. The attack vector is network-based with low complexity and requires no user interaction. The vulnerability was addressed in version 3.19.10.
Affected products
- AA Web Servant 12 Step Meeting List <= 3.19.9
Timeline
- 2026-02-20: other: Reported by Bao - BlueRock
- 2026-03-22: advisory: Patchstack advisory published
- 2026-04-08: disclosed: CVE published
- 2026-03-22: patched: Version 3.19.10 released to address the issue