Impact
The vulnerability is an unauthenticated Server Side Request Forgery (SSRF) that allows an attacker to supply arbitrary URLs to the WordPress 3D Flipbook PDF Viewer & Embedder plugin. By sending crafted requests to the plugin’s URL‑handling endpoint, an attacker can force the server to initiate requests to any network host reachable from the server, potentially exposing internal data or facilitating further attacks. The weakness is classified as CWE‑918, representing improper handling of user‑supplied URLs.
Affected Systems
The affected product is the WordPress plugin 3D Flipbook PDF Viewer & Embedder, developed by Shahadat Hossain. Versions 1.4.2 and earlier are vulnerable; the documented fix requires upgrading to version 1.4.4 or later.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity vulnerability. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw without authentication by submitting crafted URLs through the plugin’s interface, allowing them to reach any network address to which the server has connectivity. The risk is primarily that internal resources could be accessed or sensitive data exfiltrated if the server can reach internal networks.
OpenCVE Enrichment