Impact
The vulnerability is an improper neutralization of input during Web page generation, allowing stored XSS through the Real 3D FlipBook plugin. Arbitrary malicious scripts can be rendered when a page using the plugin is viewed, potentially compromising user sessions, defacing content or injecting tracking code. The weakness is classified as CWE‑79.
Affected Systems
The plugin Real 3D FlipBook from creativeinteractivemedia is affected in all releases up to and including version 4.11.4. Any WordPress site that has this plugin installed and has enabled its content generation features is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate-severity flaw, and the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The flaw is not listed in the CISA KEV catalog. The likely attack vector is through malicious content injected via the plugin’s storage mechanisms; an attacker with the ability to inject data – for example through a form or admin interface – can cause it to be persisted and later executed in users’ browsers.
OpenCVE Enrichment