Real 3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder [real3d-flipbook-lite] <= 4.16.4 (unfixed)
unknown
[en] Missing Authorization vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real 3D FlipBook: from n/a through <= 4.16.4.
- Affected:
- up to 4.16.4
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25423 on NVD →
Real 3D FlipBook <= 4.19.1 - Missing Authorization
medium
The Real 3D FlipBook plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.19.1. This makes it possible for authenticated attackers, with author-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 4.19.1
- Fixed in:
- 4.19.2
- Disclosed:
- Feb 10, 2026
CVE-2026-25423 on NVD →
Real 3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder [real3d-flipbook-lite] <= 4.11.4 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Stored XSS.This issue affects Real 3D FlipBook: from n/a through <= 4.11.4.
- Affected:
- up to 4.11.4
- Fix:
- No patched version reported
- Disclosed:
- Dec 24, 2025
CVE-2025-68512 on NVD →
Real 3D FlipBook <= 4.11.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Real 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.11.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page...
- CVSS:
- 6.4
- Affected:
- up to 4.11.4
- Fixed in:
- 4.16.4
- Disclosed:
- Dec 22, 2025
CVE-2025-68512 on NVD →
Real 3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder [real3d-flipbook-lite] < 4.8.5
unknown
[en] The 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'r3dfb_save_thumbnail_callback' function in all versions up to, and including, 4.6. This makes it possible for authenticated attacker...
- Affected:
- up to 4.8.5
- Fixed in:
- 4.8.5
- Disclosed:
- Nov 16, 2024
CVE-2024-9849 on NVD →
Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder <= 4.8 - Authenticated (Author+) Arbitrary File Upload
high
The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'r3dfb_save_thumbnail_callback' function in all versions up to, and including, 4.8. This makes it possible for authenticated attackers, with Author-lev...
- CVSS:
- 8.8
- Affected:
- up to 4.8
- Fixed in:
- 4.8.5
- Disclosed:
- Nov 15, 2024
CVE-2024-9849 on NVD →
Real 3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder [real3d-flipbook-lite] < 3.72
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative interactive media 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin allows Stored XSS.This issue affects 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin:...
- Affected:
- up to 3.72
- Fixed in:
- 3.72
- Disclosed:
- May 8, 2024
CVE-2024-34561 on NVD →
3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin <= 3.71 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.71 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level acc...
- CVSS:
- 6.4
- Affected:
- up to 3.71
- Fixed in:
- 3.72
- Disclosed:
- May 7, 2024
CVE-2024-34561 on NVD →
Real 3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder [real3d-flipbook-lite] < 3.63
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative interactive media 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin allows Reflected XSS.This issue affects 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugi...
- Affected:
- up to 3.63
- Fixed in:
- 3.63
- Disclosed:
- Apr 22, 2024
CVE-2024-32694 on NVD →
3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin <= 3.62 - Reflected Cross-Site Scripting
medium
The 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.62 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...
- CVSS:
- 6.1
- Affected:
- up to 3.62
- Fixed in:
- 3.63
- Disclosed:
- Apr 19, 2024
CVE-2024-32694 on NVD →
Real 3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder [real3d-flipbook-lite] <= 1.0
unknown
[en] The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion.
- Affected:
- up to 1.0
- Fixed in:
- 1.0
- Disclosed:
- Sep 16, 2019
CVE-2016-10965 on NVD →
Real 3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder [real3d-flipbook-lite] <= 1.0
unknown
[en] The real3d-flipbook-lite plugin 1.0 for WordPress has bookName=../ directory traversal for file upload.
- Affected:
- up to 1.0
- Fixed in:
- 1.0
- Disclosed:
- Sep 16, 2019
CVE-2016-10966 on NVD →
Real 3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder [real3d-flipbook-lite] <= 1.0
unknown
[en] The real3d-flipbook-lite plugin 1.0 for WordPress has XSS via the wp-content/plugins/real3d-flipbook/includes/flipbooks.php bookId parameter.
- Affected:
- up to 1.0
- Fixed in:
- 1.0
- Disclosed:
- Sep 16, 2019
CVE-2016-10967 on NVD →
Real 3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder [real3d-flipbook-lite] < 1.1
unknown
Real3D FlipBook plugin is prone to multiple vulnerabilities, such as XSS. An attacker can upload images in root directory and delete any files from the server.
Update WordPress plugin to the newest stable and safe version.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Jul 4, 2016
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database