plugin

Ipages Flipbook Vulnerabilities

13 known security issues reported for the Ipages Flipbook WordPress plugin. Most recent disclosed Jun 10, 2024.

1 high 3 medium

Running Ipages Flipbook on your site? Check whether your installed version is affected.

Scan your site free

iPages &#8211; FlipBook Image &amp; PDF Viewer [ipages-flipbook] < 1.5.2

unknown

[en] Missing Authorization vulnerability in Avirtum iPages Flipbook.This issue affects iPages Flipbook: from n/a through 1.5.1.

Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
Jun 10, 2024

CVE-2024-4744 on NVD →

iPages Flipbook <= 1.5.1 - Missing Authorization

medium

The iPages Flipbook plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on a REST API endpoint in versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to view deactivated items. CVE-2024-4744 may be a duplicate of this issue.

CVSS:
5.3
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Apr 29, 2024

CVE-2024-33909 on NVD →

iPages &#8211; FlipBook Image &amp; PDF Viewer [ipages-flipbook] < 1.5.0

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum iPages Flipbook For WordPress.This issue affects iPages Flipbook For WordPress: from n/a through 1.4.8.

Affected:
up to 1.5.0
Fixed in:
1.5.0
Disclosed:
Dec 20, 2023

CVE-2023-47236 on NVD →

iPages Flipbook < 1.5.0 - Authenticated (Administrator+) SQL Injection

high

The iPages Flipbook For WordPress plugin for WordPress is vulnerable to SQL Injection via the orderby parameter in all versions up to 1.5.0 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta...

CVSS:
7.2
Affected:
up to 1.5.0
Fixed in:
1.5.0
Disclosed:
Nov 3, 2023

CVE-2023-47236 on NVD →

iPages &#8211; FlipBook Image &amp; PDF Viewer [ipages-flipbook] < 1.5.0

unknown

The iPages Flipbook For WordPress plugin for WordPress is vulnerable to SQL Injection via the orderby parameter in all versions up to 1.5.0 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta...

Affected:
up to 1.5.0
Fixed in:
1.5.0
Disclosed:
Nov 3, 2023

iPages &#8211; FlipBook Image &amp; PDF Viewer [ipages-flipbook] < 1.4.7

unknown

[en] The iPages Flipbook For WordPress plugin through 1.4.6 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 1.4.7
Fixed in:
1.4.7
Disclosed:
Jan 9, 2023

CVE-2022-4394 on NVD →

iPages Flipbook <= 1.4.6 - Authenticated Contributor+ Stored Cross-Site Scripting via Shortcode

medium

The iPages Flipbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its shortcode in versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrar...

CVSS:
6.4
Affected:
up to 1.4.6
Fixed in:
1.4.7
Disclosed:
Dec 19, 2022

CVE-2022-4394 on NVD →

iPages &#8211; FlipBook Image &amp; PDF Viewer [ipages-flipbook] < 1.4.7

unknown

The iPages Flipbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its shortcode in versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrar...

Affected:
up to 1.4.7
Fixed in:
1.4.7
Disclosed:
Dec 19, 2022

iPages Flipbook < 1.4.3 - Reflected Cross-Site Scripting

medium

The iPages Flipbook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions before 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...

CVSS:
6.1
Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
Oct 11, 2021

iPages &#8211; FlipBook Image &amp; PDF Viewer [ipages-flipbook] < 1.4.3

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress iPages Flipbook plugin (versions <= 1.4.2).

Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
Oct 11, 2021

iPages &#8211; FlipBook Image &amp; PDF Viewer [ipages-flipbook] < 1.4.3

unknown

The iPages Flipbook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions before 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...

Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
Oct 11, 2021

iPages &#8211; FlipBook Image &amp; PDF Viewer [ipages-flipbook] < 1.4.3

unknown

Most plugins (both free and premium) from the Avirtum author do not escape a page parameter before outputting it back in attributes, leading to Reflected Cross-Site Scripting issues. The issues were reported to the vendor on August 4th, 2021

Affected:
up to 1.4.3
Fixed in:
1.4.3

iPages &#8211; FlipBook Image &amp; PDF Viewer [ipages-flipbook] < 1.5.2

unknown
Affected:
up to 1.5.2
Fixed in:
1.5.2

CVE-2024-33909 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database