๐Ÿ” CVE Alert

CVE-2026-88825

UNKNOWN 0.0

iGMS Direct Booking < 2.0 - Unauthenticated Stored XSS via Widget Settings

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowing unauthenticated users to store arbitrary web scripts that execute in the context of an administrator viewing the iGMS Direct Booking WordPress plugin before 2.0 settings, and in the browser of any visitor to a page displaying the booking widget.

Vendor unknown
Product igms direct booking
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for unknown igms direct booking

Be the first to know when new unknown vulnerabilities affecting unknown igms direct booking are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / iGMS Direct Booking
0 < 2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/12337af6-e465-4010-a54d-be92a5dfa5d6/

Credits

Enrico Marcolini - Claudio Marchesini - Dottor Marc WPScan