The CVE record for CVE-2026-39570 was published on 2026-04-08T09:16:28.220Z and has not been modified since then. The NVD entry is currently Deferred. This vulnerability affects the 12 Step Meeting List plugin for WordPress, allowing for the retrieval of embedded sensitive data. Users should review and apply patches or mitigations as available. The vulnerability has a CVSS score of 5.3, indicating a mediu [truncated]
A Missing Authorization vulnerability was reported in the 12 Step Meeting List plugin, affecting versions from n/a through 3.19.9. This issue allows attackers to exploit incorrectly configured access control security levels. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. The CVE record was published on 2026-04-08T09:16:28.083Z and has not been modified since. The NVD entry [truncated]