Impact
This vulnerability enables an unauthenticated attacker to read sensitive data exposed by the 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery plugin in versions up to 1.16.20. The absence of authentication controls for the data is the root cause, leading to a confidentiality breach. The weakness is classified as Sensitive Data Exposure (CWE-497). The lack of authentication controls is inferred from the description, as no explicit authentication mechanism is mentioned for the exposed data paths.
Affected Systems
The affected product is the WordPress plugin 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery, by vendor iberezansky, with all releases through version 1.16.20 considered vulnerable. No specific operating systems were listed, so any WordPress installation hosting the vulnerable plugin is at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating moderate severity. Exploitation probability is unknown due to the missing EPSS score, but based on the inferred lack of authentication it is reasonable to assume that exploitation is straightforward for any network reachable user. It is not currently listed in the CISA KEV catalog, yet the potential for widespread attack remains because the plugin is publicly available and the exposed data could be valuable.
OpenCVE Enrichment