Code for Recovery 12 Step Meeting List Sensitive Data Exposure Vulnerability

Vulnerability

A vulnerability allowing the insertion of sensitive information into sent data has been identified in the Code for Recovery 12 Step Meeting List plugin, affecting versions through 3.16.5. This vulnerability could allow unauthorized retrieval of embedded sensitive data, which is typically not accessible to regular users.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, potentially allowing for further exploitation of other weaknesses in the system.

Remediation

Users of the Code for Recovery 12 Step Meeting List plugin should update to version 3.16.6 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
7.6
remediation
7.7
relevance
0.0
threat
0.1
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.