Impact
An attacker with Contributor privileges can craft the "lightboxtext" shortcode attribute to contain a forged </script> tag that passes through WordPress sanitization and ultimately breaks out of a JSON script block, allowing the injection of arbitrary JavaScript. When a higher‑privilege user views or previews the affected page, the malicious script runs in that user’s browser, potentially enabling session hijacking, credential theft, or defacement. The flaw is rooted in insufficient input sanitization and the omission of the JSON_HEX_TAG flag during data serialization. The vulnerability does not enable arbitrary code execution on the server but can be used to perform client‑side attacks within the context of privileged users.
Affected Systems
The Real3D Flipbook Lite plugin for WordPress, developed by Creative Interactive Media, is affected in all versions up to and including 5.1.1. Users running any of these releases should suspect the presence of the "lightboxtext" shortcode handling defect.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of exploitation as of the current data. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access at the Contributor level or higher, limiting the attack surface to site administrators and editors. The attack vector is indirect, relying on the attacker inserting malicious shortcode content which is later rendered in a privileged context, rather than a direct remote code execution vector.
OpenCVE Enrichment