Impact
The Dear Flipbook WordPress plugin is vulnerable to a stored cross‑site scripting flaw. The attacker inserts a custom HTML block that contains a crafted '.df-element' div with a data-df-lightbox attribute. When the page renders, the inner HTML of this element is passed to a parsing function that fails to escape or sanitize the content, resulting in arbitrary script execution for any visitor to the page. The vulnerability allows a malicious contributor or higher role to inject scripts, deface pages, steal session cookies, or perform other malicious actions within the context of the site.
Affected Systems
All WordPress sites that use the Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, or PDF viewer plugin versions up to and including 2.4.30 are affected. The plugin is distributed by dearhive under the DearFlip name. Sites that permit contributor‑level users to add Custom HTML blocks are particularly at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to have authenticated contributor‑level or higher access to the WordPress backend, which limits the attack window but still poses a significant risk once that role is obtained. The lack of remote, unauthenticated access means the vulnerability depends on insider or compromised accounts, but the damage scope is large once exploited.
OpenCVE Enrichment