Impact
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to exposure of sensitive data through the unprotected 'id' query parameter passed to an AJAX endpoint. Because this input is not authenticated, an attacker can request the metadata of password‑protected flipbooks, retrieving the title, outline, props, and the serialized blob that contains the PDF’s direct URL. This is a CWE‑200 Sensitive Information Exposure vulnerability and bypasses WordPress post‑password protection, allowing enumeration of flipbook IDs through a separate unauthenticated AJAX action.
Affected Systems
All installations of the 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin from vendor iberezansky with versions up to and including 1.16.20 are affected. Any site that has deployed one of these versions and hosts flipbooks is vulnerable.
Risk and Exploitability
With a CVSS score of 5.3 the risk is moderate. The EPSS score of less than 1 % indicates a very low probability of exploitation at the moment, and theV catalog, so no widespread exploitation is documented. Attackers can exploit the flaw unauthenticated by sending HTTP requests to the AJAX endpoint that handles the 'id' parameter, and any flipbook ID can be discovered through a separate unauthenticated AJAX action that lists all post IDs.
OpenCVE Enrichment