Stored Cross-Site Scripting in JetAppointment Plugin for WordPress
An unauthenticated stored XSS vulnerability in the JetAppointment WordPress plugin allows attackers to inject malicious scripts via the friendlyTime parameter that execute in an administrator's browser context.
CVE search metadata
CVE search record: CVE-2026-93875. Severity: high. CVSS: 7.2. KEV: no. Product: JetAppointment (<= 2.5.2.1). Brief: Stored Cross-Site Scripting in JetAppointment Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-jetappointment-xss/
The JetAppointment plugin for WordPress, developed by Crocoblock, is vulnerable to Stored Cross-Site Scripting (XSS) in all versions up to and including 2.5.2.1. The flaw exists due to insufficient input sanitization and output escaping within the 'friendlyTime' parameter. An unauthenticated attacker can exploit this by sending a crafted HTTP POST request to the 'jet_engine_form_booking_submit' endpoint. The malicious payload is subsequently stored in the 'wp_jet_appointments_meta' database table. The payload executes in the browser of an administrator who views the appointment details within the WordPress admin dashboard, potentially leading to unauthorized administrative actions or session compromise.
Attack Chain
- An attacker identifies the target WordPress site running a vulnerable version of JetAppointment.
- The attacker crafts a malicious HTTP POST request targeting the 'jet_engine_form_booking_submit' endpoint.
- The attacker includes a JavaScript payload within the 'friendlyTime' parameter of the request body.
- The plugin fails to sanitize the input and saves the payload directly into the 'wp_jet_appointments_meta' table in the WordPress database.
- An administrator logs into the WordPress dashboard and navigates to the appointment management section.
- The plugin retrieves the malicious record and renders it in the appointment details popup.
- The administrator's browser executes the stored JavaScript, enabling further malicious activity such as account creation or privilege escalation.
Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a WordPress administrator's session. This could result in the unauthorized creation of administrative accounts, modification of site content, or the exfiltration of sensitive site configuration data. The vulnerability affects all users running JetAppointment version 2.5.2.1 or earlier.
Recommendation
Prioritized, concrete actions for detection engineering and security operations teams:
- Update the JetAppointment plugin to a patched version beyond 2.5.2.1 as soon as an update becomes available.
- Implement a Web Application Firewall (WAF) rule to block POST requests to 'jet_engine_form_booking_submit' that contain script tags or suspicious JavaScript patterns in the 'friendlyTime' parameter.
- Monitor web server access logs for anomalous POST activity to 'jet_engine_form_booking_submit' from external IP addresses.
Immediate actions
Patch JetAppointment to a version > 2.5.2.1.
Mitigations
Deploy WAF rule to filter malicious scripts in the friendlyTime parameter.
CVE-2026-93875
Detection coverage 1
Detect CVE-2026-93875 Exploitation - Stored XSS Attempt in JetAppointment
highDetects exploitation attempts against the JetAppointment plugin by identifying POST requests to the submission endpoint containing script tags in the friendlyTime parameter.
Detection queries are available on the platform. Get full rules →