WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in 12 Step Meeting List

This plugin helps twelve step recovery programs list their meetings. It standardizes addresses, and displays results in a searchable list and map.

11Reported vulnerabilities
7.2Highest CVSS score
3.19.16Latest version
900+Active installs

What to do now

Update 12 Step Meeting List to 3.19.17 or later. 11 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 21, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2026-78333 High 7.2 0.3% 3.17 to 3.19.16 (inclusive) 3.19.17 August 28, 2026
CVE-2026-66584 High 7.2 0.1% 3.19.16 and earlier 3.19.17 August 20, 2026
CVE-2023-46641 Medium 6.4 0.3% 3.14.24 and earlier 3.14.25 November 27, 2023
CVE-2025-54054 Medium 6.4 0.2% 3.18.3 and earlier 3.18.4 August 14, 2025
CVE-2024-35693 Medium 6.1 0.6% 3.14.33 and earlier 3.14.34 June 6, 2024
CVE-2025-24582 Medium 5.3 1.0% 3.16.5 and earlier 3.16.6 January 24, 2025
CVE-2026-39570 Medium 5.3 0.2% 3.19.9 and earlier 3.19.10 March 22, 2026
CVE-2025-24583 Medium 5.3 0.4% 3.16.5 and earlier 3.16.6 December 18, 2024
CVE-2024-22296 Medium 5.3 0.3% 3.14.28 and earlier 3.14.29 January 17, 2024
CVE-2025-24580 Medium 4.3 0.6% 3.16.5 and earlier 3.16.6 January 24, 2025
CVE-2026-39569 Medium 4.3 0.3% 3.19.9 and earlier 3.19.10 March 22, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.