Description
The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any user who later opens the affected flipbook for editing, including administrators.
Published: 2026-09-23
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Patch
AI Analysis

Impact

The Real3D Flipbook Lite WordPress plugin before version 5.4 contains a stored XSS flaw that fails to sanitize or escape several editor fields when rendering them back in the admin editor. A user with Author role or higher can inject arbitrary JavaScript into a flipbook, and the script will run in the browser of any user who later opens the affected flipbook for editing, including administrators.

Affected Systems

The vulnerability affects the Real3D Flipbook Lite WordPress plugin, specifically all releases prior to version 5.4.

Risk and Exploitability

The CVSS score of 6.8 indicates a medium severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an attacker have Author or higher permission within the WordPress site to create or edit a flipbook; the injected script then executes in the context of the victim’s browser when the flipbook is edited. Potential consequences include session hijack, defacement, or the delivery of additional malware, affecting the confidentiality, integrity, and availability of the site’s content for any user interacting with the flipbook.

Generated by OpenCVE AI on September 23, 2026 at 14:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Real3D Flipbook Lite to version 5.4 or newer to ensure editor fields are properly sanitized and encoded.
  • Remove or cleanse any existing flipbooks that contain injected scripts by editing them as an administrator and clearing suspicious code.
  • Restrict Author‑level access or monitor new flipbook content for unintended script injections, and enforce stricter input validation when adding or editing flipbooks.

Generated by OpenCVE AI on September 23, 2026 at 14:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any user who later opens the affected flipbook for editing, including administrators.
Title Real3D Flipbook Lite < 5.4 - Author+ Stored XSS
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T11:01:34.702Z

Reserved: 2026-09-08T14:46:47.614Z

Link: CVE-2025-15696

cve-icon Vulnrichment

Updated: 2026-09-23T10:39:52.473Z

cve-icon NVD

Status : Received

Published: 2026-09-23T06:17:00.710

Modified: 2026-09-23T11:17:09.653

Link: CVE-2025-15696

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T14:15:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')