iGMS Direct Booking
iGMS Direct Booking has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of August 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for iGMS Direct Booking has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.
All of these findings were reported by Legion Hunter. iGMS Direct Booking is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.3.10.
CVE-2026-39652iGMS Direct Booking <= 1.3 - Missing Authorization
Read the full analysisVulnerability Records

iGMS Direct Booking
Author
igms
iGMS is a vacation rental software that helps hosts to handle day-to-day short-term rental management tasks efficiently. With iGMS, users can operate Airbnb and Vrbo accounts, as well as Booking.com properties via a single interface, with access to the same advanced functionality through the mobile app. On average, our users see a 34% increase in the number of reservations and are able to automate up to 70% of their daily communication. Our most popular features: Channel manager Unified inbox Tools for team coordination Automated guest messaging and message templates Payment processing Automated guest reviews for Airbnb Detailed financial reporting Direct booking management toolkit With the iGMS Direct Booking Widget, you can: Allow your guests to make reservations directly via your website Process payments for your direct bookings via Stripe Make sure your direct bookings sync with the rest of your channels Make your communication with direct booking guests flawless with the power of automation You can check out the Direct Booking Widget in action on the following website: vancouverdirect.igms.com The Direct Booking Widget is developed by iGMS. By using the plugin, you agree to the iGMS terms of use. All reservations created and accepted through the Direct Booking Widget are stored, managed, and processed by iGMS in accordance with the privacy policy. iGMS is committed to securing your data.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C