plugin

Interactive 3D Flipbook Powered Physics Engine Vulnerabilities

26 known security issues reported for the Interactive 3D Flipbook Powered Physics Engine WordPress plugin. Most recent disclosed Apr 14, 2026.

1 high 15 medium

Running Interactive 3D Flipbook Powered Physics Engine on your site? Check whether your installed version is affected.

Scan your site free

3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.17 - Missing Authorization to Unauthenticated Private/Draft Flipbook Data Exposure

medium

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the send_post_pages_json() function in all versions up to, and including, 1.16.17. This makes it possible for unauthenticated attackers to re...

CVSS:
5.3
Affected:
up to 1.16.17
Fixed in:
1.16.18
Disclosed:
Apr 14, 2026

CVE-2026-1314 on NVD →

3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.16 - Unauthenticated Sensitive Information Exposure

medium

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.16. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 1.16.16
Fixed in:
1.16.17
Disclosed:
Sep 22, 2025

CVE-2025-58226 on NVD →

3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery < 1.16.17 - Unauthenticated Sensitive Information Exposure

medium
Affected:
up to 1.16.17
Fixed in:
1.16.17
Disclosed:
Sep 22, 2025

CVE-2025-58226 on NVD →

3D FlipBook - Lite Edition <= 1.16.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via style and mode Parameters

medium

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ and 'mode' parameters in all versions up to, and including, 1.16.15 due to insufficient input sanitization and output escaping. This makes it possible for authent...

CVSS:
6.4
Affected:
up to 1.16.15
Fixed in:
1.16.16
Disclosed:
Jun 20, 2025

CVE-2025-5289 on NVD →

3D FlipBook - Lite Edition < 1.16.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via style and mode Parameters

medium
Affected:
up to 1.16.16
Fixed in:
1.16.16
Disclosed:
Jun 20, 2025

CVE-2025-5289 on NVD →

3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.15.7 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in iberezansky 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery allows Stored XSS.This issue affects 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery: from n/a through 1.15.6.

Affected:
up to 1.15.7
Fixed in:
1.15.7
Disclosed:
Aug 12, 2024

CVE-2024-43152 on NVD →

3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.15.6 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 1.15.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to...

CVSS:
4.4
Affected:
up to 1.15.6
Fixed in:
1.15.7
Disclosed:
Aug 7, 2024

CVE-2024-43152 on NVD →

3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery < 1.15.7 - Authenticated (Editor+) Stored Cross-Site Scripting

medium
Affected:
up to 1.15.7
Fixed in:
1.15.7
Disclosed:
Aug 7, 2024

CVE-2024-43152 on NVD →

3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.15.6 (closed)

unknown

[en] A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

Affected:
up to 1.15.6
Fixed in:
1.15.6
Disclosed:
May 14, 2024

CVE-2024-4367 on NVD →

3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.15.5 (closed)

unknown

[en] The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Bookmark URL field in all versions up to, and including, 1.15.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arb...

Affected:
up to 1.15.5
Fixed in:
1.15.5
Disclosed:
May 2, 2024

CVE-2024-3883 on NVD →

3D FlipBook <= 1.15.4 - Authenticated (Author+) Stored Cross-Site Scritping via Bookmark URL

medium

The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Bookmark URL field in all versions up to, and including, 1.15.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrar...

CVSS:
6.4
Affected:
up to 1.15.4
Fixed in:
1.15.5
Disclosed:
May 1, 2024

CVE-2024-3883 on NVD →

3D FlipBook < 1.15.5 - Authenticated (Author+) Stored Cross-Site Scritping via Bookmark URL

unknown
Affected:
up to 1.15.5
Fixed in:
1.15.5
Disclosed:
May 1, 2024

CVE-2024-3883 on NVD →

3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.15.4 (closed)

unknown

[en] The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bookmark feature in all versions up to, and including, 1.15.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-l...

Affected:
up to 1.15.4
Fixed in:
1.15.4
Disclosed:
Feb 21, 2024

CVE-2024-1081 on NVD →

3D FlipBook – PDF Flipbook WordPress <= 1.15.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Bookmarks

medium

The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bookmark feature in all versions up to, and including, 1.15.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level...

CVSS:
6.4
Affected:
up to 1.15.3
Fixed in:
1.15.4
Disclosed:
Feb 20, 2024

CVE-2024-1081 on NVD →

3D FlipBook – PDF Flipbook WordPress < 1.15.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Bookmarks

medium
Affected:
up to 1.15.4
Fixed in:
1.15.4
Disclosed:
Feb 20, 2024

CVE-2024-1081 on NVD →

3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.15.3 (closed)

unknown

[en] The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Ready Function’ field in all versions up to, and including, 1.15.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to i...

Affected:
up to 1.15.3
Fixed in:
1.15.3
Disclosed:
Jan 11, 2024

CVE-2023-6776 on NVD →

3D Flipbook <= 1.15.2 - Authenticated (Contributor+) Cross-Site Scripting via Ready Function

medium

The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Ready Function’ field in all versions up to, and including, 1.15.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject...

CVSS:
6.4
Affected:
up to 1.15.2
Fixed in:
1.15.3
Disclosed:
Jan 2, 2024

CVE-2023-6776 on NVD →

3D Flipbook < 1.15.3 - Contributor+ Stored XSS

medium
Affected:
up to 1.15.3
Fixed in:
1.15.3
Disclosed:
Jan 2, 2024

CVE-2023-6776 on NVD →

3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.13.3 (closed)

unknown

[en] The 3D FlipBook WordPress plugin through 1.13.2 does not validate or escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks against high privilege users like administrators.

Affected:
up to 1.13.3
Fixed in:
1.13.3
Disclosed:
Jan 16, 2023

CVE-2022-4453 on NVD →

3D FlipBook <= 1.13.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.13.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level permiss...

CVSS:
6.4
Affected:
up to 1.13.2
Fixed in:
1.13.3
Disclosed:
Dec 22, 2022

CVE-2022-4453 on NVD →

3D FlipBook < 1.13.3 - Contributor+ Stored XSS

medium
Affected:
up to 1.13.3
Fixed in:
1.13.3
Disclosed:
Dec 22, 2022

CVE-2022-4453 on NVD →

3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.12.1 (closed)

unknown

[en] The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads in all pages with a 3d flipbook.

Affected:
up to 1.12.1
Fixed in:
1.12.1
Disclosed:
Mar 21, 2022

CVE-2022-0423 on NVD →

3D FlipBook <= 1.12.0 - Subscriber+ Stored Cross-Site Scripting

medium

The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads in all pages with a 3d flipbook.

CVSS:
6.4
Affected:
up to 1.12.1
Fixed in:
1.12.1
Disclosed:
Feb 28, 2022

CVE-2022-0423 on NVD →

3D FlipBook < 1.12.1 - Subscriber+ Stored Cross-Site Scripting

high
Affected:
up to 1.12.1
Fixed in:
1.12.1
Disclosed:
Feb 28, 2022

CVE-2022-0423 on NVD →

3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] <= 1.16.16 (unfixed)

unknown
Affected:
up to 1.16.16
Fix:
No patched version reported

CVE-2025-58226 on NVD →

3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery [interactive-3d-flipbook-powered-physics-engine] < 1.16.16 (closed)

unknown
Affected:
up to 1.16.16
Fixed in:
1.16.16

CVE-2025-5289 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database