Junglewise Threat Intelligence

CVE-2026-7662: ePaperFlip Publisher Stored XSS in epaperflip_embed shortcode

CVE-2026-7662 · Severity: medium · CVSS 6.4 · Published 2026-06-09

Executive brief

The ePaperFlip Publisher plugin for WordPress, which allows users to embed digital publications, contains a security flaw that allows authenticated users to inject malicious scripts into website pages. An attacker with basic contributor-level access could use this to run unauthorized code in the browsers of other site visitors or administrators. This could lead to unauthorized actions being performed on behalf of other users or the theft of sensitive session information.

Technical details

The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'publicationid' attribute of the `epaperflip_embed` shortcode. This attribute is injected directly into inline JavaScript without proper neutralization. An authenticated attacker with Contributor-level permissions or higher can exploit this by embedding a malicious shortcode into a post or page. When other users, including administrators, view the affected page, the injected script executes in their browser context. The plugin was temporarily closed on the WordPress repository in June 2026 pending review.

Affected products

  • joshin85 ePaperFlip Publisher up to, and including, 1

Timeline

  • 2026-06-03: other: Plugin temporarily closed on WordPress.org repository
  • 2026-06-09: disclosed: CVE published to NVD dataset

References