Junglewise Threat Intelligence

CVE-2024-33909: Avirtum iPages Flipbook missing authorization in access control

CVE-2024-33909 · Severity: medium · CVSS 5.3 · Published 2026-06-17

Executive brief

Avirtum iPages Flipbook is a WordPress plugin used to create interactive digital flipbooks from PDFs or images. A security flaw in the plugin allows unauthorized individuals to bypass intended access controls, potentially allowing them to view content or perform actions that should be restricted to administrators. This could lead to the exposure of private documents or unauthorized changes to flipbook configurations.

Technical details

A Broken Access Control vulnerability (CWE-862: Missing Authorization) exists in the Avirtum iPages Flipbook plugin for WordPress. The flaw stems from a failure to properly validate user permissions or implement sufficient authorization checks on specific functions. An unauthenticated remote attacker can exploit this by sending crafted requests to the affected site, potentially bypassing security levels intended to restrict access to certain features or data. The vulnerability is addressed in version 1.5.2.

Affected products

  • Avirtum iPages Flipbook up to 1.5.1

Timeline

  • 2024-01-22: other: Vulnerability reported by researcher
  • 2024-04-29: advisory: Patchstack published advisory
  • 2024-04-29: patched: Version 1.5.2 released to address the issue
  • 2026-06-17: disclosed: NVD publication date

References