What the vulnerability does
01Description
Missing Authorization vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through 3.14.28.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Code for Recovery 12 Step Meeting List.This issue affects 12 Step Meeting List: from n/a through 3.14.28.
Explanation of Vulnerability in Simple Terms
The 12 Step Meeting List plugin through version 3.14.28 does not properly restrict access to certain functions based on user roles. A logged-in user with low privileges can read sensitive meeting information they should not have access to. The vulnerability requires authentication but no special user interaction.
What an attacker can do
Read meeting data and information they should not have access to based on their user role.
Potential impact on your site
Sensitive meeting information may be exposed to unauthorized users with basic site accounts.
Conditions required to exploit
Attacker must have a low-privilege account on the site (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities