Skip to content
Security & Trust

JetAppointment flaw lets anonymous visitors plant code in admin screens

A public booking form stores text that runs when a WordPress administrator opens appointment details.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
JetAppointment flaw lets anonymous visitors plant code in admin screens

AI-generated image for WebPulse. About our images

In brief
  • NIST's database lists CVE-2026-93875, a stored cross-site scripting flaw in the JetAppointment WordPress plugin, in all versions up to and including 2.5.2.1.
  • Anonymous visitors can submit text that later runs in an administrator's browser. The danger sits in the admin screen that trusts public input.
  • Check whether you run the plugin and which version. Then read the vendor changelog and look for unexpected script in stored appointment data.

A booking form is built to be open. Anyone can fill it in, and no account is needed. The risk starts when what a stranger typed later appears on a screen your staff trust. That is the situation described in CVE-2026-93875, a flaw in the JetAppointment plugin for WordPress.

The record sits in the NIST National Vulnerability Database. It was published on October 2, 2026. The affected range runs through version 2.5.2.1, and every release up to that one is covered. The score was assigned by Wordfence ([email protected]).

How the flaw works

The plugin accepts a booking value called friendlyTime. According to the record, the jet_engine_form_booking_submit endpoint takes that request without a login. The plugin saves the value in a database table named wp_jet_appointments_meta.

Nothing happens at that point. The harm comes later, when an administrator opens the appointment details popup in the WordPress admin panel. The stored text then runs as script in the administrator's browser.

This type of flaw is called stored cross-site scripting. Two safeguards should stop it. Sanitization cleans input on the way in. Escaping makes sure text is shown as text on the way out, and not run as code. The record says both are insufficient here.

The screen that trusts the form

The deeper weakness is the trusted screen that shows stranger-supplied text without treating it as foreign. The record faults input handling too. Still, a form is meant to accept input from strangers. The display is where that input meets someone trusted.

Think of mail in an office. The mailroom expects anything to arrive. The risk begins when a letter is read aloud in the boardroom as if a colleague wrote it. An admin dashboard is that boardroom. Code that runs there runs in a browser where the administrator is signed in.

The record does not say what an attacker could do with that access. It does not say the flaw is being exploited. It does not give the number of sites running the plugin.

7.2 (HIGH)
CVSS 3.1 base score
Source: NIST NVD record CVE-2026-93875, scored by [email protected] (October 2, 2026)
2.5.2.1
Last affected version
Source: NIST NVD record CVE-2026-93875 (October 2, 2026)

What the score says and leaves out

The vector reads AV:N/AC:L/PR:N. In plain words, the attack comes over the network, is not complex, and needs no privileges. It also marks the scope as changed. That fits the mechanism: the flaw sits in the plugin, but the effect lands in the administrator's browser.

One detail deserves a careful read. The vector lists no user interaction. The description says the code runs when an administrator opens the popup. The record does not explain how the two fit together.

The impact ratings are low for confidentiality and integrity, and none for availability. A score of 7.2 describes the flaw in general. It cannot tell you what a signed-in administrator at your organization could expose.

Questions to put to your team

The NVD record lists two references: the Crocoblock changelog for the plugin and a Wordfence entry. Start there.

First, do we run JetAppointment, and which version? Any version at or below 2.5.2.1 is in scope. Second, what does the vendor changelog say about a fix, and who owns applying it? Third, have we looked at the stored appointment data for unexpected script? Fourth, which administrator accounts open appointment details, and what else are they signed in to at the time?

A form decides who may speak. The screen decides who gets believed.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: NIST NVD.

Share this insight