plugin

Real3D Flipbook Vulnerabilities

10 known security issues reported for the Real3D Flipbook WordPress plugin. Most recent disclosed Jul 3, 2016.

2 critical 1 high 3 medium

Running Real3D Flipbook on your site? Check whether your installed version is affected.

Scan your site free

Real3D Flipbook <= 1.0.0 - Directory Traversal

critical

The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion.

CVSS:
9.1
Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
Jul 3, 2016

CVE-2016-10965 on NVD →

Real3D Flipbook <= 1.0.0 - File Upload to User Controlled Location

high

The Real3D Flipbook plugin for WordPress is vulnerable to file uploads to user controlled locations due to missing directory validation in the 'bookName' parameter in versions up to, and including, 1.0.0 This makes it possible for attackers to upload files to arbitrary locations on the affected sites server.

CVSS:
7.5
Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
Jul 3, 2016

CVE-2016-10966 on NVD →

Real3D Flipbook <= 2.8 - Reflected Cross-Site Scripting via bookId parameter

medium

The Real3D Flipbook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘bookId’ parameter in versions up to, and including, 2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 2.9
Fixed in:
2.9
Disclosed:
Jul 3, 2016

Real3D Flipbook <= 1.0 - Reflected Cross-Site Scripting

medium

The real3d-flipbook-lite plugin 1.0 for WordPress has XSS via the wp-content/plugins/real3d-flipbook/includes/flipbooks.php bookId parameter.

CVSS:
6.1
Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
Jul 3, 2016

CVE-2016-10967 on NVD →

Real3D Flipbook [real3d-flipbook] < 2.9

unknown

The Real3D Flipbook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘bookId’ parameter in versions up to, and including, 2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

Affected:
up to 2.9
Fixed in:
2.9
Disclosed:
Jul 3, 2016

Real3D Flipbook <= 2.8 - Unauthenticated Arbitrary File or Directory Delete

critical

The Real3D Flipbook plugin for WordPress is vulnerable to Unauthenticated File or Directory Delete in versions up to, and including, 2.8. This is due to missing privilege checks. This makes it possible for unauthenticated attackers to delete arbitrary files or folders on the site.

CVSS:
10
Affected:
up to 2.9
Fixed in:
2.9
Disclosed:
Jul 2, 2016

Real3D Flipbook <= 2.8 - Directory Traversal via Uploads

medium

The Real3D Flipbook plugin for WordPress is vulnerable to Directory Traversal via uploads in versions up to, and including, 2.8. This is due to missing path validation checks. This makes it possible for authenticated attackers to upload image files into root, which could potentially lead to deletion of arbitrary files...

CVSS:
4.1
Affected:
up to 2.9
Fixed in:
2.9
Disclosed:
Jul 2, 2016

Real3D Flipbook [real3d-flipbook] < 2.9

unknown

The Real3D Flipbook plugin for WordPress is vulnerable to Unauthenticated File or Directory Delete in versions up to, and including, 2.8. This is due to missing privilege checks. This makes it possible for unauthenticated attackers to delete arbitrary files or folders on the site.

Affected:
up to 2.9
Fixed in:
2.9
Disclosed:
Jul 2, 2016

Real3D Flipbook [real3d-flipbook] < 2.9

unknown

The Real3D Flipbook plugin for WordPress is vulnerable to Directory Traversal via uploads in versions up to, and including, 2.8. This is due to missing path validation checks. This makes it possible for authenticated attackers to upload image files into root, which could potentially lead to deletion of arbitrary files...

Affected:
up to 2.9
Fixed in:
2.9
Disclosed:
Jul 2, 2016

Real3D Flipbook [real3d-flipbook] < 2.9

unknown

List of vulnerabilities: - Delete any file or directory from the server (Unauthenticated) - Upload images in Root directory (Unauthenticated) - Cross-Site Scripting (XSS)

Affected:
up to 2.9
Fixed in:
2.9

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database