{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/jetappointment--2.5.2.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:crocoblock:jetappointment:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-93875"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["JetAppointment (\u003c= 2.5.2.1)"],"_cs_severities":["high"],"_cs_tags":["xss","web-application","wordpress","cve-2026-93875"],"_cs_type":"advisory","_cs_vendors":["Crocoblock"],"content_html":"\u003cp\u003eThe JetAppointment plugin for WordPress, developed by Crocoblock, is vulnerable to Stored Cross-Site Scripting (XSS) in all versions up to and including 2.5.2.1. The flaw exists due to insufficient input sanitization and output escaping within the 'friendlyTime' parameter. An unauthenticated attacker can exploit this by sending a crafted HTTP POST request to the 'jet_engine_form_booking_submit' endpoint. The malicious payload is subsequently stored in the 'wp_jet_appointments_meta' database table. The payload executes in the browser of an administrator who views the appointment details within the WordPress admin dashboard, potentially leading to unauthorized administrative actions or session compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies the target WordPress site running a vulnerable version of JetAppointment.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP POST request targeting the 'jet_engine_form_booking_submit' endpoint.\u003c/li\u003e\n\u003cli\u003eThe attacker includes a JavaScript payload within the 'friendlyTime' parameter of the request body.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to sanitize the input and saves the payload directly into the 'wp_jet_appointments_meta' table in the WordPress database.\u003c/li\u003e\n\u003cli\u003eAn administrator logs into the WordPress dashboard and navigates to the appointment management section.\u003c/li\u003e\n\u003cli\u003eThe plugin retrieves the malicious record and renders it in the appointment details popup.\u003c/li\u003e\n\u003cli\u003eThe administrator's browser executes the stored JavaScript, enabling further malicious activity such as account creation or privilege escalation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a WordPress administrator's session. This could result in the unauthorized creation of administrative accounts, modification of site content, or the exfiltration of sensitive site configuration data. The vulnerability affects all users running JetAppointment version 2.5.2.1 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering and security operations teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the JetAppointment plugin to a patched version beyond 2.5.2.1 as soon as an update becomes available.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to block POST requests to 'jet_engine_form_booking_submit' that contain script tags or suspicious JavaScript patterns in the 'friendlyTime' parameter.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST activity to 'jet_engine_form_booking_submit' from external IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T14:25:22Z","date_published":"2026-10-02T14:25:22Z","id":"https://feed.craftedsignal.io/briefs/2026-10-jetappointment-xss/","summary":"An unauthenticated stored XSS vulnerability in the JetAppointment WordPress plugin allows attackers to inject malicious scripts via the friendlyTime parameter that execute in an administrator's browser context.","title":"Stored Cross-Site Scripting in JetAppointment Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-10-jetappointment-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - JetAppointment (\u003c= 2.5.2.1)","version":"https://jsonfeed.org/version/1.1"}