Description
The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowing unauthenticated users to store arbitrary web scripts that execute in the context of an administrator viewing the iGMS Direct Booking WordPress plugin before 2.0 settings, and in the browser of any visitor to a page displaying the booking widget.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS execution in admin and visitor contexts
Action: Upgrade Plugin
AI Analysis

Impact

The iGMS Direct Booking WordPress plugin before version 2.0 omits permission checks and escaping on its widget appearance settings, enabling unauthenticated users to inject arbitrary JavaScript that is stored and later executed whenever an administrator views the widget settings or any visitor loads a page containing the booking widget. The primary consequence is client‑side script execution with the privileges of the viewer, allowing session hijacking, defacement, data exfiltration, or malicious redirection.

Affected Systems

WordPress sites running the iGMS Direct Booking plugin older than version 2.0 are affected. The vendor is iGMS Direct Booking; no precise release range is listed beyond "< 2.0".

Risk and Exploitability

This flaw carries a CVSS score of 8.8, indicating a high severity. The EPSS score of < 1% suggests that current exploitation attempts are very low, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, if a site is publicly exposed, an attacker can achieve stored XSS by submitting payloads through the widget settings page, which will then be served to privileged admins or site visitors, enabling client‑side compromise. The attack vector is likely through the publicly accessible widget settings page, and an exploit does not require authentication to store the payload, but it does require that the victim later view the widget or its settings to trigger execution.

Generated by OpenCVE AI on September 19, 2026 at 19:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade iGMS Direct Booking to version 2.0 or later to remove the unauthenticated input handling flaw.
  • If upgrading is not immediately possible, block or delete the widget settings page and disable the widget on front‑end pages to prevent execution of stored scripts.
  • Apply a Content Security Policy that restricts inline script execution and limits script sources for the site, or use WordPress output sanitization functions to escape any remaining plugin output.
  • Review WordPress role definitions to ensure only administrators can access plugin settings and consider adding additional permission checks for widget configuration.

Generated by OpenCVE AI on September 19, 2026 at 19:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions igms Direct Booking
Vendors & Products Wordpress-extensions
Wordpress-extensions igms Direct Booking

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowing unauthenticated users to store arbitrary web scripts that execute in the context of an administrator viewing the iGMS Direct Booking WordPress plugin before 2.0 settings, and in the browser of any visitor to a page displaying the booking widget.
Title iGMS Direct Booking < 2.0 - Unauthenticated Stored XSS via Widget Settings
References

Subscriptions

Wordpress-extensions Igms Direct Booking
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T11:08:58.073Z

Reserved: 2026-09-10T09:30:24.509Z

Link: CVE-2026-88825

cve-icon Vulnrichment

Updated: 2026-09-18T11:01:21.595Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T06:16:41.157

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-88825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T13:21:43Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')