3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.17 - Missing Authorization to Unauthenticated Private/Draft Flipbook Data Exposure
medium
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the send_post_pages_json() function in all versions up to, and including, 1.16.17. This makes it possible for unauthenticated attackers to re...
- CVSS:
- 5.3
- Affected:
- up to 1.16.17
- Fixed in:
- 1.16.18
- Disclosed:
- Apr 14, 2026
CVE-2026-1314 on NVD →
3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.16 - Unauthenticated Sensitive Information Exposure
medium
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.16. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 1.16.16
- Fixed in:
- 1.16.17
- Disclosed:
- Sep 22, 2025
CVE-2025-58226 on NVD →
3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery < 1.16.17 - Unauthenticated Sensitive Information Exposure
medium
- Affected:
- up to 1.16.17
- Fixed in:
- 1.16.17
- Disclosed:
- Sep 22, 2025
CVE-2025-58226 on NVD →
3D FlipBook - Lite Edition <= 1.16.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via style and mode Parameters
medium
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ and 'mode' parameters in all versions up to, and including, 1.16.15 due to insufficient input sanitization and output escaping. This makes it possible for authent...
- CVSS:
- 6.4
- Affected:
- up to 1.16.15
- Fixed in:
- 1.16.16
- Disclosed:
- Jun 20, 2025
CVE-2025-5289 on NVD →
3D FlipBook - Lite Edition < 1.16.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via style and mode Parameters
medium
- Affected:
- up to 1.16.16
- Fixed in:
- 1.16.16
- Disclosed:
- Jun 20, 2025
CVE-2025-5289 on NVD →
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.15.7 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in iberezansky 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery allows Stored XSS.This issue affects 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery: from n/a through 1.15.6.
- Affected:
- up to 1.15.7
- Fixed in:
- 1.15.7
- Disclosed:
- Aug 12, 2024
CVE-2024-43152 on NVD →
3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.15.6 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 1.15.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to...
- CVSS:
- 4.4
- Affected:
- up to 1.15.6
- Fixed in:
- 1.15.7
- Disclosed:
- Aug 7, 2024
CVE-2024-43152 on NVD →
3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery < 1.15.7 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
- Affected:
- up to 1.15.7
- Fixed in:
- 1.15.7
- Disclosed:
- Aug 7, 2024
CVE-2024-43152 on NVD →
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.15.6 (closed)
unknown
[en] A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
- Affected:
- up to 1.15.6
- Fixed in:
- 1.15.6
- Disclosed:
- May 14, 2024
CVE-2024-4367 on NVD →
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.15.5 (closed)
unknown
[en] The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Bookmark URL field in all versions up to, and including, 1.15.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arb...
- Affected:
- up to 1.15.5
- Fixed in:
- 1.15.5
- Disclosed:
- May 2, 2024
CVE-2024-3883 on NVD →
3D FlipBook <= 1.15.4 - Authenticated (Author+) Stored Cross-Site Scritping via Bookmark URL
medium
The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Bookmark URL field in all versions up to, and including, 1.15.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrar...
- CVSS:
- 6.4
- Affected:
- up to 1.15.4
- Fixed in:
- 1.15.5
- Disclosed:
- May 1, 2024
CVE-2024-3883 on NVD →
3D FlipBook < 1.15.5 - Authenticated (Author+) Stored Cross-Site Scritping via Bookmark URL
unknown
- Affected:
- up to 1.15.5
- Fixed in:
- 1.15.5
- Disclosed:
- May 1, 2024
CVE-2024-3883 on NVD →
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.15.4 (closed)
unknown
[en] The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bookmark feature in all versions up to, and including, 1.15.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-l...
- Affected:
- up to 1.15.4
- Fixed in:
- 1.15.4
- Disclosed:
- Feb 21, 2024
CVE-2024-1081 on NVD →
3D FlipBook – PDF Flipbook WordPress <= 1.15.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Bookmarks
medium
The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bookmark feature in all versions up to, and including, 1.15.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level...
- CVSS:
- 6.4
- Affected:
- up to 1.15.3
- Fixed in:
- 1.15.4
- Disclosed:
- Feb 20, 2024
CVE-2024-1081 on NVD →
3D FlipBook – PDF Flipbook WordPress < 1.15.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Bookmarks
medium
- Affected:
- up to 1.15.4
- Fixed in:
- 1.15.4
- Disclosed:
- Feb 20, 2024
CVE-2024-1081 on NVD →
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.15.3 (closed)
unknown
[en] The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Ready Function’ field in all versions up to, and including, 1.15.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to i...
- Affected:
- up to 1.15.3
- Fixed in:
- 1.15.3
- Disclosed:
- Jan 11, 2024
CVE-2023-6776 on NVD →
3D Flipbook <= 1.15.2 - Authenticated (Contributor+) Cross-Site Scripting via Ready Function
medium
The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Ready Function’ field in all versions up to, and including, 1.15.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject...
- CVSS:
- 6.4
- Affected:
- up to 1.15.2
- Fixed in:
- 1.15.3
- Disclosed:
- Jan 2, 2024
CVE-2023-6776 on NVD →
3D Flipbook < 1.15.3 - Contributor+ Stored XSS
medium
- Affected:
- up to 1.15.3
- Fixed in:
- 1.15.3
- Disclosed:
- Jan 2, 2024
CVE-2023-6776 on NVD →
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.13.3 (closed)
unknown
[en] The 3D FlipBook WordPress plugin through 1.13.2 does not validate or escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks against high privilege users like administrators.
- Affected:
- up to 1.13.3
- Fixed in:
- 1.13.3
- Disclosed:
- Jan 16, 2023
CVE-2022-4453 on NVD →
3D FlipBook <= 1.13.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.13.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level permiss...
- CVSS:
- 6.4
- Affected:
- up to 1.13.2
- Fixed in:
- 1.13.3
- Disclosed:
- Dec 22, 2022
CVE-2022-4453 on NVD →
3D FlipBook < 1.13.3 - Contributor+ Stored XSS
medium
- Affected:
- up to 1.13.3
- Fixed in:
- 1.13.3
- Disclosed:
- Dec 22, 2022
CVE-2022-4453 on NVD →
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.12.1 (closed)
unknown
[en] The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads in all pages with a 3d flipbook.
- Affected:
- up to 1.12.1
- Fixed in:
- 1.12.1
- Disclosed:
- Mar 21, 2022
CVE-2022-0423 on NVD →
3D FlipBook <= 1.12.0 - Subscriber+ Stored Cross-Site Scripting
medium
The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads in all pages with a 3d flipbook.
- CVSS:
- 6.4
- Affected:
- up to 1.12.1
- Fixed in:
- 1.12.1
- Disclosed:
- Feb 28, 2022
CVE-2022-0423 on NVD →
3D FlipBook < 1.12.1 - Subscriber+ Stored Cross-Site Scripting
high
- Affected:
- up to 1.12.1
- Fixed in:
- 1.12.1
- Disclosed:
- Feb 28, 2022
CVE-2022-0423 on NVD →
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] <= 1.16.16 (unfixed)
unknown
- Affected:
- up to 1.16.16
- Fix:
- No patched version reported
CVE-2025-58226 on NVD →
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.16.16 (closed)
unknown
- Affected:
- up to 1.16.16
- Fixed in:
- 1.16.16
CVE-2025-5289 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database