Executive brief
The Real3D Flipbook Lite WordPress plugin fails to properly sanitize user input in shortcode attributes, allowing authenticated contributors to inject malicious scripts into pages. When site editors or administrators preview or moderate content containing the injected code, the malicious scripts execute with their privileges, potentially leading to unauthorized actions or data theft.
Technical details
The vulnerability exists in the on_shortcode() and print_global_options() functions, where shortcode attribute values are copied into flipbook_options and emitted via wp_json_encode() without the JSON_HEX_TAG flag inside a script context. An attacker with Contributor access can bypass the save-time wp_kses_post filter by encoding the breakout sequence as escaped characters (e.g., \x3c/script\x3e), which are decoded to literal HTML at render time, allowing them to break out of the JSON script block and inject arbitrary JavaScript.
Affected products
- Real3D Flipbook Lite up to and including 5.1.1
Timeline
- 2026-09-19: disclosed