Executive brief
Real3D Flipbook is a WordPress plugin that creates interactive 3D flipbook documents. The plugin fails to sanitize user input in flipbook editor fields, allowing authors and higher-privileged users to inject malicious scripts. When an administrator later edits the flipbook, the injected script executes in their browser, potentially enabling account takeover or unauthorized actions.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in the flipbook editor fields caused by insufficient input sanitization and output escaping. An authenticated user with Author role or above can inject arbitrary JavaScript into flipbook configuration fields, which persists in the database and executes when any user (including administrators) loads the editor interface. The vulnerability requires prior authentication and user interaction to trigger the payload.
Affected products
- Real3D Flipbook before 5.4
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Fixed in version 5.4