Description
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including the full metadata payload of password-protected flipbooks — including title, outline, props, and the serialized data blob containing the underlying PDF file's direct URL — bypassing WordPress post-password confidentiality. Flipbook post IDs can be pre-enumerated via the also-unauthenticated fb3d_send_posts AJAX action, requiring no prior knowledge to target specific flipbooks.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Exposure
Action: Patch Now
AI Analysis

Impact

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to exposure of sensitive data through the unprotected 'id' query parameter passed to an AJAX endpoint. Because this input is not authenticated, an attacker can request the metadata of password‑protected flipbooks, retrieving the title, outline, props, and the serialized blob that contains the PDF’s direct URL. This is a CWE‑200 Sensitive Information Exposure vulnerability and bypasses WordPress post‑password protection, allowing enumeration of flipbook IDs through a separate unauthenticated AJAX action.

Affected Systems

All installations of the 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin from vendor iberezansky with versions up to and including 1.16.20 are affected. Any site that has deployed one of these versions and hosts flipbooks is vulnerable.

Risk and Exploitability

With a CVSS score of 5.3 the risk is moderate. The EPSS score of less than 1 % indicates a very low probability of exploitation at the moment, and theV catalog, so no widespread exploitation is documented. Attackers can exploit the flaw unauthenticated by sending HTTP requests to the AJAX endpoint that handles the 'id' parameter, and any flipbook ID can be discovered through a separate unauthenticated AJAX action that lists all post IDs.

Generated by OpenCVE AI on September 17, 2026 at 18:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery to any version newer than 1.16.20. If a patch is not yet available, temporarily disable the plugin or remove it from production sites that host sensitive flipbooks.
  • Restrict access to the AJAX endpoint that processes the 'id' parameter using web‑application firewall rules or .htaccess directives so that only legitimate requests from trusted hosts can reach it.
  • Implement logging and alerting for requests to the plugin’s AJAX endpoint to detect enumeration or data exfiltration attempts and respond accordingly.

Generated by OpenCVE AI on September 17, 2026 at 18:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Description The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including the full metadata payload of password-protected flipbooks — including title, outline, props, and the serialized data blob containing the underlying PDF file's direct URL — bypassing WordPress post-password confidentiality. Flipbook post IDs can be pre-enumerated via the also-unauthenticated fb3d_send_posts AJAX action, requiring no prior knowledge to target specific flipbooks.
Title 3D FlipBook <= 1.16.20 - Unauthenticated Sensitive Information Exposure in 'id' Parameter
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-17T13:55:34.665Z

Reserved: 2026-07-14T16:37:00.739Z

Link: CVE-2026-15758

cve-icon Vulnrichment

Updated: 2026-09-17T13:55:29.125Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T06:16:54.020

Modified: 2026-09-17T14:17:12.260

Link: CVE-2026-15758

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor