PT-2026-91859 · WordPress · 3D Flipbook
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery versions prior to 1.16.21
Description
Unauthenticated attackers can extract sensitive data from password-protected flipbooks by exploiting the
id parameter. This allows the retrieval of the full metadata payload, including the title, outline, props, and the serialized data blob containing the direct URL of the underlying PDF file, which bypasses WordPress post-password confidentiality. Additionally, flipbook post IDs can be pre-enumerated using the unauthenticated fb3d send posts AJAX action.Recommendations
Update the plugin to a version later than 1.16.20.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
3D Flipbook