S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 19, 2025

CVE-2024-35693 Scanner

CVE-2024-35693 Scanner - Cross-Site Scripting vulnerability in WordPress 12 Step Meeting List Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-35693
6.1
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list.This issue affects 12 Step Meeting List: from n/a through <= 3.14.33.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
12 Step Meeting Listby AA Web Servant
0
Updated Aug 22, 2026View on NVD →
Detail

The WordPress 12 Step Meeting List Plugin is utilized widely by organizations offering 12-step meeting information and scheduling. Users implement this plugin to streamline meeting management on WordPress sites. It enhances the user experience by allowing site visitors to easily find and interact with meeting data. Developers integrate this plugin to ensure seamless functionality on WordPress platforms. Its popularity stems from its ability to handle complex meeting details efficiently. The plugin is crucial for organizations aiming to disseminate meeting information accurately and effectively.

Cross-Site Scripting (XSS) is a widespread vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users. This vulnerability stems from improper input neutralization during web page generation, as evidenced in the WordPress 12 Step Meeting List Plugin. The XSS flaw typically requires the attacker to trick a user into clicking a crafted URL. Once executed, this script can access any cookies, session tokens, or other sensitive data retained by the user's browser. Moreover, XSS vulnerabilities can escalate to more severe attacks such as user impersonation.

The vulnerability in this plugin involves a reflected XSS flaw located at the endpoint serving meeting data. Attackers can exploit this by appending a malicious script to URLs, particularly in the 'tsml-query' parameter. For the payload to execute, a user must navigate to the crafted URL. The vulnerability primarily targets the plugin's failure to properly sanitize and securely encode outputs. Successful exploitation returns malicious scripting that executes in the context of a user's browser, integral for carrying out further attacks.

Upon exploitation, malicious actors can execute scripts to steal sensitive user information, including cookies and session tokens. They may carry out actions in the user's browser without their consent. This could lead to unauthorized data manipulation, session hijacking, or impersonation, significantly affecting user privacy and security. The vulnerability might also open up more pathways for further exploitation, escalating into a broader security risk for the affected platform. Addressing this issue is crucial to prevent data breaches or malicious leading actions in user sessions.

REFERENCES

Solution Advice
  • Ensure all input fields are sanitized properly and that output data is securely encoded to prevent XSS.
  • Regularly update the plugin and apply security patches provided by the developers.
  • Educate users about the dangers of clicking on suspicious links or URLs from untrusted sources.
  • Implement content security policy headers to mitigate XSS exploits where feasible.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.