Executive brief
The 3D FlipBook plugin for WordPress, used to embed and display PDF flipbooks and image galleries on websites, allows unauthenticated attackers to extract sensitive metadata from password-protected flipbooks. Attackers can bypass access controls to retrieve titles, outlines, embedded PDF URLs, and other confidential data without requiring any authentication or user interaction.
Technical details
The vulnerability is a sensitive information exposure flaw in the 'id' parameter handling that fails to enforce WordPress post-password protection on flipbook metadata. An unauthenticated attacker can query flipbook post IDs (which can be enumerated via the fb3d_send_posts AJAX action) and retrieve the complete metadata payload, including serialized data containing the direct URL to underlying PDF files. The vulnerability affects all versions up to and including 1.16.20, requires only network access with no authentication or user interaction, and allows complete bypass of WordPress password confidentiality controls.
Affected products
- 3D FlipBook 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery up to and including 1.16.20
Timeline
- 2026-09-15: disclosed