Impact
The JetAppointment plugin for WordPress is vulnerable to a stored Cross‑Site Scripting attack via the 'friendlyTime' parameter. Because the input is not properly sanitized or escaped before being written to the wp_jet_appointments_meta database table, an attacker can store malicious JavaScript. When an administrator opens the appointment details popup in the WordPress admin panel, the injected script executes in the administrator’s browser, potentially allowing theft of session cookies, credential hijacking, or the execution of arbitrary actions on the site.
Affected Systems
The vulnerability affects all installations of the Crocoblock JetAppointment plugin up to and including version 2.5.2.1 running on WordPress. No specific environment constraints are listed; the issue exists regardless of whether the site is publicly accessible or behind a firewall.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests a moderate likelihood of exploitation in the immediate term. Attackers can trigger the flaw by sending an unauthenticated HTTP request to the jet_engine_form_booking_submit endpoint with a crafted 'friendlyTime' value. The payload is stored in the database and later executed in an administrator’s browser, giving the attacker a convenient vector for further malicious activity if the admin consents to the popup. Because authentication is not required to submit the payload, breadth of impact is potentially wide across sites using a vulnerable plugin version.
OpenCVE Enrichment