Description
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.
Published: 2026-07-27
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated Server Side Request Forgery (SSRF) that allows an attacker to supply arbitrary URLs to the WordPress 3D Flipbook PDF Viewer & Embedder plugin. By sending crafted requests to the plugin’s URL‑handling endpoint, an attacker can force the server to initiate requests to any network host reachable from the server, potentially exposing internal data or facilitating further attacks. The weakness is classified as CWE‑918, representing improper handling of user‑supplied URLs.

Affected Systems

The affected product is the WordPress plugin 3D Flipbook PDF Viewer & Embedder, developed by Shahadat Hossain. Versions 1.4.2 and earlier are vulnerable; the documented fix requires upgrading to version 1.4.4 or later.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity vulnerability. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw without authentication by submitting crafted URLs through the plugin’s interface, allowing them to reach any network address to which the server has connectivity. The risk is primarily that internal resources could be accessed or sensitive data exfiltrated if the server can reach internal networks.

Generated by OpenCVE AI on August 3, 2026 at 17:33 UTC.

Remediation

Vendor Solution

Update the WordPress 3D Flipbook PDF Viewer &amp; Embedder Plugin to the latest available version (at least 1.4.4).


OpenCVE Recommended Actions

  • Update the WordPress 3D Flipbook PDF Viewer & Embedder plugin to version 1.4.4 or later.
  • If an update is not immediately possible, disable the plugin until the issue is resolved to stop the plugin from processing arbitrary URLs.
  • Restrict outbound network connections from the WordPress server, limiting access to only trusted domains, to reduce the impact of any remaining SSRF vectors.

Generated by OpenCVE AI on August 3, 2026 at 17:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Shahadat Hossain
Shahadat Hossain 3d Flipbook Pdf Viewer &amp; Embedder
Wordpress
Wordpress wordpress
Vendors & Products Shahadat Hossain
Shahadat Hossain 3d Flipbook Pdf Viewer &amp; Embedder
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.
Title WordPress 3D Flipbook PDF Viewer & Embedder plugin <= 1.4.2 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Shahadat Hossain 3d Flipbook Pdf Viewer &amp; Embedder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T16:18:02.783Z

Reserved: 2026-07-05T21:28:04.586Z

Link: CVE-2026-59552

cve-icon Vulnrichment

Updated: 2026-07-27T15:10:54.570Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:05.350

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-59552

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:45:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)