Security Alert Summary
The JetAppointment plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject JavaScript via a booking parameter. The payload can be stored in the plugin data table and will execute in an administrator’s browser when appointment details are viewed in the WordPress admin panel.
CVE Details
- CVE ID: CVE-2026-93875
- Affected component: JetAppointment (plugin for WordPress)
- Affected versions: All versions up to and including 2.5.2.1
- Published: October 2, 2026 at 2:17:11 PM UTC
- Last modified: October 2, 2026 at 2:17:11 PM UTC
- CVSS v3.1 base score: 7.2
- Severity: HIGH
- Vector string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Authentication / privileges / user interaction: No authentication required; privileges required: none; user interaction: none (unauthenticated attacker)
- Primary impact: Confidentiality: Low; Integrity: Low; Availability: None
- CWE / weakness: CWE-79 (Improper Neutralization of Input During Web Page Generation)
Technical Details
This vulnerability is a stored cross-site scripting issue caused by insufficient input sanitization and output escaping of the friendlyTime parameter. An unauthenticated request to the plugin endpoint jet_engine_form_booking_submit can store attacker-supplied script payloads into the wp_jet_appointments_meta table. When an administrator opens the appointment details popup in the WordPress admin panel, the stored payload is rendered and executes in the administrator’s browser context.
The issue exists because input provided via the booking submission endpoint is not properly validated or escaped before being persisted and later output in the admin UI. The impact is limited to the confidentiality and integrity of data accessible to the administrator’s browser (for example, session-based actions or displayed information), and does not indicate direct availability impact based on the provided data.
How This Could Impact Your Website
Consider a site where external users or unauthenticated visitors can submit appointments through public booking forms. An attacker could submit a booking containing a malicious friendlyTime value that is stored in plugin data. When an administrator, editor, or staff member opens the appointment details popup, the injected script runs in their browser. In a practical scenario this could lead to exposure of data visible to that admin session, or enable actions that affect the integrity of displayed information.
Potential practical consequences include exposure of internal user email addresses listed in the admin UI and an increased risk of targeted phishing or social engineering against staff and contractors who access appointment data. If youre unsure whether your site is affected or how to assess your current user roles and plugins, it may be worth having a professional review.
Recommended Actions
- Update the affected plugin as soon as a patched version is available.
- Review and reduce unnecessary user roles, especially contributor-level and other non-admin roles that can be targeted.
- Enforce strong passwords and two-factor authentication for editors and administrators.
- Remove unused or unmaintained plugins.
- Monitor site activity and admin actions for unusual behavior or unexpected appointment entries.
If youd like help reviewing your plugins, user roles, or overall WordPress security posture, our team at Freshy is happy to help.