Junglewise Threat Intelligence

CVE-2026-59552: Shahadat Hossain 3D Flipbook PDF Viewer & Embedder SSRF

CVE-2026-59552 · Severity: high · CVSS 7.2 · Published 2026-07-27

Executive brief

A vulnerability exists in the 3D Flipbook PDF Viewer & Embedder plugin for WordPress, which is used to display interactive PDF documents on websites. An unauthenticated attacker can exploit this flaw to force the web server to make unauthorized requests to internal or external systems. This could lead to the exposure of sensitive internal data or allow the server to be used as a proxy for further attacks against other infrastructure.

Technical details

The 3D Flipbook PDF Viewer & Embedder plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.4.2. The flaw allows an unauthenticated remote attacker to send crafted requests that cause the server to initiate network connections to arbitrary domains or internal IP addresses. This occurs due to insufficient validation of user-supplied URLs used by the plugin's PDF rendering or embedding functionality. Successful exploitation can lead to information disclosure of internal services or unauthorized interaction with internal network resources. The issue is addressed in version 1.4.4.

Affected products

  • Shahadat Hossain (Patchstack) 3D Flipbook PDF Viewer & Embedder <= 1.4.2

Timeline

  • 2026-01-31: other: Reported by Nabil Irawan
  • 2026-07-23: advisory: Patchstack advisory published
  • 2026-07-27: disclosed: CVE published to NVD dataset

References