PT-2026-95778 · WordPress · Real3D-Flipbook-Lite
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Real3D Flipbook Lite versions prior to 5.1.2
Description
Stored Cross-Site Scripting is possible due to insufficient input sanitization and output escaping in the
on shortcode() and print global options() functions. The issue occurs when shortcode attribute values, such as lightboxtext, are copied into $this->flipbook options and emitted via wp json encode() within a script block without the JSON HEX TAG flag. This allows a literal </script> sequence to break the JSON script context. Authenticated attackers with Contributor-level access or higher can bypass save-time filters by encoding the breakout tag, enabling the injection of arbitrary web scripts that execute when a user with higher privileges, such as an Editor or Administrator, views the affected page.Recommendations
Update Real3D Flipbook Lite to version 5.1.2 or later.
As a temporary mitigation, restrict the ability of users with Contributor-level access to edit shortcode attributes until the update is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Real3D-Flipbook-Lite