Impact
The iGMS Direct Booking WordPress plugin before version 2.0 omits permission checks and escaping on its widget appearance settings, enabling unauthenticated users to inject arbitrary JavaScript that is stored and later executed whenever an administrator views the widget settings or any visitor loads a page containing the booking widget. The primary consequence is client‑side script execution with the privileges of the viewer, allowing session hijacking, defacement, data exfiltration, or malicious redirection.
Affected Systems
WordPress sites running the iGMS Direct Booking plugin older than version 2.0 are affected. The vendor is iGMS Direct Booking; no precise release range is listed beyond "< 2.0".
Risk and Exploitability
This flaw carries a CVSS score of 8.8, indicating a high severity. The EPSS score of < 1% suggests that current exploitation attempts are very low, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, if a site is publicly exposed, an attacker can achieve stored XSS by submitting payloads through the widget settings page, which will then be served to privileged admins or site visitors, enabling client‑side compromise. The attack vector is likely through the publicly accessible widget settings page, and an exploit does not require authentication to store the payload, but it does require that the victim later view the widget or its settings to trigger execution.
OpenCVE Enrichment