Impact
The Nature FlipBook plugin contains a reflected XSS flaw (CWE‑79) where user supplied data is not properly escaped before being reflected in the page output. An attacker can construct a crafted query or form input that causes malicious JavaScript to execute in the victim’s browser, enabling cookie theft, defacement, or arbitrary client‑side code execution, thereby compromising confidentiality and integrity of the user environment. This flaw does not grant code execution on the server.
Affected Systems
The flashmaniac Nature FlipBook WordPress plugin (Nature FlipBook) is vulnerable across all versions up to and including 1.7. No later versions are known to be affected.
Risk and Exploitability
With a CVSS score of 7.1 this issue falls into the medium severity range. The EPSS score of less than 1% indicates the likelihood of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog. The advised attack vector is remote: an attacker can entice a victim to click a forged URL or submit a malicious form that the plugin fails to sanitize. Successful exploitation results in execution of JavaScript in the victim’s browser but does not grant server‑side code execution.
OpenCVE Enrichment
EUVD