PT-2026-97155 · WordPress · Real 3D Flipbook
CVE-2025-15696
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Real3D Flipbook versions prior to 5.4
Description
Insufficient sanitization and escaping of several flipbook editor fields allow users with the Author role and above to perform a stored cross-site scripting attack. This occurs when arbitrary web scripts are injected into the editor fields and subsequently execute in the browser of any user, including administrators, who opens the affected flipbook for editing.
Recommendations
Update the plugin to version 5.4 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Real 3D Flipbook