Description
The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is stored in the wp_jet_appointments_meta table via the unauthenticated jet_engine_form_booking_submit endpoint and executes in the administrator's browser when the appointment details popup is opened in the WordPress admin panel.
Published: 2026-10-02
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The JetAppointment plugin for WordPress is vulnerable to a stored Cross‑Site Scripting attack via the 'friendlyTime' parameter. Because the input is not properly sanitized or escaped before being written to the wp_jet_appointments_meta database table, an attacker can store malicious JavaScript. When an administrator opens the appointment details popup in the WordPress admin panel, the injected script executes in the administrator’s browser, potentially allowing theft of session cookies, credential hijacking, or the execution of arbitrary actions on the site.

Affected Systems

The vulnerability affects all installations of the Crocoblock JetAppointment plugin up to and including version 2.5.2.1 running on WordPress. No specific environment constraints are listed; the issue exists regardless of whether the site is publicly accessible or behind a firewall.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests a moderate likelihood of exploitation in the immediate term. Attackers can trigger the flaw by sending an unauthenticated HTTP request to the jet_engine_form_booking_submit endpoint with a crafted 'friendlyTime' value. The payload is stored in the database and later executed in an administrator’s browser, giving the attacker a convenient vector for further malicious activity if the admin consents to the popup. Because authentication is not required to submit the payload, breadth of impact is potentially wide across sites using a vulnerable plugin version.

Generated by OpenCVE AI on October 2, 2026 at 15:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the JetAppointment plugin to the latest available release that removes the input sanitization flaw.
  • If an upgrade is not immediately feasible, restrict the jet_engine_form_booking_submit endpoint to authenticated users or disable form booking submissions from unauthenticated visitors.
  • Apply site‑wide input validation and output escaping rules—particularly for the friendlyTime parameter—using a security‑oriented plugin or custom code to prevent storage of malicious scripts.

Generated by OpenCVE AI on October 2, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 13:45:00 +0000

Type Values Removed Values Added
Description The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is stored in the wp_jet_appointments_meta table via the unauthenticated jet_engine_form_booking_submit endpoint and executes in the administrator's browser when the appointment details popup is opened in the WordPress admin panel.
Title JetAppointment <= 2.5.2.1 - Unauthenticated Stored Cross-Site Scripting via 'friendlyTime' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T13:42:19.583Z

Reserved: 2026-09-18T19:51:12.955Z

Link: CVE-2026-93875

cve-icon Vulnrichment

Updated: 2026-10-02T13:42:14.869Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T14:17:11.850

Modified: 2026-10-02T17:52:32.600

Link: CVE-2026-93875

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T15:15:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')