Executive brief
DearFlip is a WordPress plugin used to create interactive 3D flipbooks from PDF files and images. A security flaw in the plugin's access control settings allows users with low-level accounts, such as contributors, to bypass intended restrictions. This could lead to unauthorized access to content or settings that should be restricted to administrators.
Technical details
A missing authorization vulnerability (CWE-862) exists in the DearHive DearFlip plugin for WordPress through version 2.4.27. The flaw stems from insufficient validation of user permissions when accessing certain functions or security levels. An authenticated attacker with 'Contributor' level privileges can exploit this misconfiguration to perform actions or access data that should be restricted to higher-privileged users. The attack is reachable over the network and does not require user interaction. As of the advisory date, no official patch has been released.
Affected products
- DearHive DearFlip (3D Flipbook) <= 2.4.27
Timeline
- 2026-02-07: other: Vulnerability reported by researcher
- 2026-05-27: advisory: Published by Patchstack and NVD