The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the …
Medium CVSS 5.3
Summary
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including the full metadata payload of password-protected flipbooks — including title, outline, props, and the serialized data blob containing the underlying PDF file's direct URL — bypassing WordPress pos…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://plugins.trac.wordpress.org/browser/interactive-3d-flipbook-powered-physics-engine/trunk/inc/ajax-get.php#L119
- https://plugins.trac.wordpress.org/browser/interactive-3d-flipbook-powered-physics-engine/trunk/inc/ajax-get.php#L136
- https://plugins.trac.wordpress.org/browser/interactive-3d-flipbook-powered-physics-engine/trunk/inc/ajax-get.php#L142
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3661282%40interactive-3d-flipbook-powered-physics-engine&new=3661282%40interactive-3d-flipbook-powered-physics-engine
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3ad65e10-6f99-421b-abec-ed374769dfcf?source=cve
Timeline
- nvd_ingest NVD