Sceawere

Vulnerability Detail

CVE-2026-93875UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JetAppointment Stored Cross-Site Scripting

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
9h ago
Vendor
Crocoblock
Product
JetAppointment
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is stored in the wp_jet_appointments_meta table via the unauthenticated jet_engine_form_booking_submit endpoint and executes in the administrator's browser when the appointment details popup is opened in the WordPress admin panel.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-02T14:17:11.850Z",
  "pubdate": "2026-10-02T14:17:11.850Z",
  "executiveSummary": "The JetAppointment plugin for WordPress contains a critical Stored Cross-Site Scripting (XSS) vulnerability affecting versions up to and including 2.5.2.1.\nThis vulnerability stems from insufficient input sanitization and inadequate output escaping within the 'friendlyTime' parameter.\nUnauthenticated attackers can inject arbitrary JavaScript payloads into the application via the 'jet_engine_form_booking_submit' endpoint.\nThe malicious script is persisted within the 'wp_jet_appointments_meta' database table.\nExecution occurs within the administrative context of the WordPress dashboard when an administrator views appointment details.\nThis creates a high-risk scenario, allowing for potential account takeover, unauthorized administrative actions, or session hijacking through the execution of malicious scripts in a privileged user's browser session.",
  "technicalDetails": "The vulnerability originates from the improper handling of user-supplied data in the 'friendlyTime' parameter during the appointment booking process. The plugin fails to sanitize this input before storing it in the 'wp_jet_appointments_meta' table via the 'jet_engine_form_booking_submit' endpoint.\nThe exploitation process is initiated by an unauthenticated attacker who submits a crafted booking request. The payload, embedded within the 'friendlyTime' field, is processed by the backend and committed to the database without validation. Because the endpoint does not require authentication, any remote attacker can perform this injection.\nThe execution phase occurs asynchronously. When an authorized administrator navigates to the WordPress admin panel and accesses the appointment management interface, the plugin retrieves the malicious payload from the database and renders it directly into the DOM (Document Object Model) of the administrative page. The browser then interprets the injected script as legitimate content, executing the payload in the context of the administrator's authenticated session.\nThis vulnerability is classified as Stored XSS because the script persists on the server and executes upon viewing the compromised resource. The impact is significant because it grants the attacker the ability to execute arbitrary code within the victim's browser, potentially leading to administrative session hijacking, unauthorized modifications to site configurations, or the redirection of traffic to malicious external domains. The lack of output encoding/escaping at the point of injection or rendering constitutes the core flaw in the software's input/output lifecycle."
}
CVE-2026-93875: JetAppointment Stored Cross-Site Scripting (HIGH Severity, CVSS: 7.2) | Sceawere