<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-93875 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-93875/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 14:25:22 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-93875/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in JetAppointment Plugin for WordPress</title><link>https://feed.craftedsignal.io/briefs/2026-10-jetappointment-xss/</link><pubDate>Fri, 02 Oct 2026 14:25:22 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-jetappointment-xss/</guid><description>An unauthenticated stored XSS vulnerability in the JetAppointment WordPress plugin allows attackers to inject malicious scripts via the friendlyTime parameter that execute in an administrator's browser context.</description><content:encoded><![CDATA[<p>The JetAppointment plugin for WordPress, developed by Crocoblock, is vulnerable to Stored Cross-Site Scripting (XSS) in all versions up to and including 2.5.2.1. The flaw exists due to insufficient input sanitization and output escaping within the 'friendlyTime' parameter. An unauthenticated attacker can exploit this by sending a crafted HTTP POST request to the 'jet_engine_form_booking_submit' endpoint. The malicious payload is subsequently stored in the 'wp_jet_appointments_meta' database table. The payload executes in the browser of an administrator who views the appointment details within the WordPress admin dashboard, potentially leading to unauthorized administrative actions or session compromise.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An attacker identifies the target WordPress site running a vulnerable version of JetAppointment.</li>
<li>The attacker crafts a malicious HTTP POST request targeting the 'jet_engine_form_booking_submit' endpoint.</li>
<li>The attacker includes a JavaScript payload within the 'friendlyTime' parameter of the request body.</li>
<li>The plugin fails to sanitize the input and saves the payload directly into the 'wp_jet_appointments_meta' table in the WordPress database.</li>
<li>An administrator logs into the WordPress dashboard and navigates to the appointment management section.</li>
<li>The plugin retrieves the malicious record and renders it in the appointment details popup.</li>
<li>The administrator's browser executes the stored JavaScript, enabling further malicious activity such as account creation or privilege escalation.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a WordPress administrator's session. This could result in the unauthorized creation of administrative accounts, modification of site content, or the exfiltration of sensitive site configuration data. The vulnerability affects all users running JetAppointment version 2.5.2.1 or earlier.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for detection engineering and security operations teams:</p>
<ul>
<li>Update the JetAppointment plugin to a patched version beyond 2.5.2.1 as soon as an update becomes available.</li>
<li>Implement a Web Application Firewall (WAF) rule to block POST requests to 'jet_engine_form_booking_submit' that contain script tags or suspicious JavaScript patterns in the 'friendlyTime' parameter.</li>
<li>Monitor web server access logs for anomalous POST activity to 'jet_engine_form_booking_submit' from external IP addresses.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>xss</category><category>web-application</category><category>wordpress</category><category>cve-2026-93875</category></item></channel></rss>