Impact
The vulnerability is an unauthenticated cross‑site scripting flaw in the Real 3D FlipBook WordPress plugin up to version 5.5. Based on the description, it is inferred that an attacker could inject arbitrary JavaScript into pages served by the plugin, potentially enabling session hijacking, credential theft, or defacement. Based on the use of CWE‑79, it is inferred that the flaw stems from improper input validation and output encoding.
Affected Systems
The affected vendor is Creative interactive media and the product the Real 3D FlipBook WordPress plugin. All installations running version 5.5 or earlier are vulnerable; a fixed version has not yet been identified in the provided data.
Risk and Exploitability
The flaw carries a CVSS score of 7.1, indicating a high severity. The EPSS score is unavailable, but the absence of an EPSS entry and the lack of listing in the CISA KEV catalog suggest that exploitation is not widely observed or currently known. Based on the description, it is inferred that the attack does not require authentication and can be performed remotely via the plugin’s web interface if the site hosts the vulnerable plugin.
OpenCVE Enrichment