PT-2026-95250 · WordPress · Igms Direct Booking
CVE-2026-88825
·
Published
2026-09-18
·
Updated
2026-09-18
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
iGMS Direct Booking versions prior to 2.0
Description
The plugin fails to authorize or escape widget appearance settings, enabling unauthenticated users to perform a Stored Cross-Site Scripting (XSS) attack. This allows the storage of arbitrary web scripts that execute within the context of an administrator viewing the plugin settings or in the browser of any visitor accessing a page that displays the booking widget.
Recommendations
Update iGMS Direct Booking to version 2.0 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Igms Direct Booking