Impact
The Real3D Flipbook Lite WordPress plugin before version 5.4 contains a stored XSS flaw that fails to sanitize or escape several editor fields when rendering them back in the admin editor. A user with Author role or higher can inject arbitrary JavaScript into a flipbook, and the script will run in the browser of any user who later opens the affected flipbook for editing, including administrators.
Affected Systems
The vulnerability affects the Real3D Flipbook Lite WordPress plugin, specifically all releases prior to version 5.4.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an attacker have Author or higher permission within the WordPress site to create or edit a flipbook; the injected script then executes in the context of the victim’s browser when the flipbook is edited. Potential consequences include session hijack, defacement, or the delivery of additional malware, affecting the confidentiality, integrity, and availability of the site’s content for any user interacting with the flipbook.
OpenCVE Enrichment