CVE-2026-88825: iGMS Direct Booking < 2.0 - Unauthenticated Stored XSS via Widget Settings
The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowing unauthenticated users to store arbitrary web scripts that execute in the context of an administrator viewing the iGMS Direct Booking WordPress plugin before 2.0 settings, and in the browser of any visitor to a page displaying the booking widget.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated user can store arbitrary script through the plugin's widget appearance settings; no account or prior authorization is required.
Which users are exposed to the stored script?
The script can execute when an administrator views the plugin settings and in the browsers of visitors viewing a page that displays the booking widget.
Are default deployments affected?
The available information identifies the widget appearance settings and pages displaying the booking widget as the affected areas. It does not state whether the widget is enabled or displayed by default.