high · CVSS v3 7.2
CVE-2026-93875
The JetAppointment plugin for WordPress is vulnerable to stored XSS via the friendlyTime parameter. Unauthenticated attackers can inject scr
Overview
The JetAppointment plugin for WordPress is vulnerable to stored XSS via the friendlyTime parameter. Unauthenticated attackers can inject scripts that execute in the admin panel when appointment details are opened. This allows malicious code to run in the context of administrators.
Description
The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is stored in the wp_jet_appointments_meta table via the unauthenticated jet_engine_form_booking_submit endpoint and executes in the administrator's browser when the appointment details popup is opened in the WordPress admin panel.
Impact
Confidentiality: attackers can exfiltrate data via injected scripts. Integrity: malicious code can alter the admin UI or inject content. Availability: not directly impacted. Impacted parties: WordPress site administrators and users accessing appointment pages.
Remediation
Update JetAppointment to version 2.5.2.2 or later. If update is not possible, disable the jet_engine_form_booking_submit endpoint or restrict it to authenticated users only. Sanitize the friendlyTime input and escape output in templates. Monitor the wp_jet_appointments_meta table for unexpected scripts.
Risk context
High severity with CVSS 7.2 indicates significant risk. No EPSS data is available. Defenders should prioritize patching or mitigation promptly.
Affected products
- WordPress
- JetAppointment plugin
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- —