Executive brief
A security flaw exists in the iGMS Direct Booking plugin for WordPress, which is used to manage vacation rental bookings. This vulnerability allows unauthorized individuals to bypass intended security restrictions due to improperly configured access controls. An attacker could potentially perform actions or access settings that should be restricted to website administrators, potentially disrupting booking operations.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the iGMS Direct Booking plugin (igms-direct-booking) for WordPress through version 1.3. The issue stems from incorrectly configured access control security levels within the plugin's functions. A remote, unauthenticated attacker can exploit this flaw to execute actions that should require higher privileges. As of the advisory date, no official patch has been released, and users are advised to monitor for updates or implement web application firewall (WAF) rules to mitigate unauthorized access to plugin functions.
Affected products
- igms iGMS Direct Booking <= 1.3
Timeline
- 2026-01-16: other: Vulnerability reported by researcher
- 2026-02-15: advisory: Initial advisory published by Patchstack
- 2026-04-08: disclosed: CVE published to NVD