Executive brief
The iGMS Direct Booking WordPress plugin is used by website owners to display a property booking widget. Before version 2.0, the plugin fails to validate or secure widget appearance settings, allowing attackers to inject malicious scripts that execute whenever an administrator views the plugin settings or when any visitor browses a page with the booking widget displayed.
Technical details
This is an unauthenticated stored cross-site scripting (XSS) vulnerability in the widget appearance settings of the iGMS Direct Booking WordPress plugin versions before 2.0. The plugin accepts and stores user-supplied input in widget configuration without proper authorization checks or output escaping, allowing any unauthenticated attacker to inject arbitrary JavaScript. The injected scripts persist in the database and execute in two contexts: (1) when administrators access the plugin settings dashboard, and (2) when any website visitor loads a page displaying the booking widget. An attacker can exploit this to steal administrative session tokens, deface the website, harvest visitor data, or redirect users to malicious sites. The vulnerability is fixed in version 2.0 and later.
Affected products
- iGMS Direct Booking before 2.0
Timeline
- 2026-09-16: disclosed: Publicly disclosed
- 2026-09: patched: Fixed in version 2.0