PT-2026-95778 · WordPress · Real3D-Flipbook-Lite

·

CVE-2026-15098

·

Published

2026-09-19

·

Updated

2026-09-19

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Real3D Flipbook Lite versions prior to 5.1.2
Description Stored Cross-Site Scripting is possible due to insufficient input sanitization and output escaping in the on shortcode() and print global options() functions. The issue occurs when shortcode attribute values, such as lightboxtext, are copied into $this->flipbook options and emitted via wp json encode() within a script block without the JSON HEX TAG flag. This allows a literal </script> sequence to break the JSON script context. Authenticated attackers with Contributor-level access or higher can bypass save-time filters by encoding the breakout tag, enabling the injection of arbitrary web scripts that execute when a user with higher privileges, such as an Editor or Administrator, views the affected page.
Recommendations Update Real3D Flipbook Lite to version 5.1.2 or later. As a temporary mitigation, restrict the ability of users with Contributor-level access to edit shortcode attributes until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15098

Affected Products

Real3D-Flipbook-Lite