Junglewise Threat Intelligence

CVE-2026-86842: Real3D Flipbook WordPress plugin authorization bypass and stored XSS

CVE-2026-86842 · Severity: medium · CVSS 6.8 · Published 2026-09-23

Executive brief

The Real3D Flipbook WordPress plugin before version 5.4 fails to properly check user permissions on critical administration actions. This allows lower-privileged authors to delete other users' flipbooks and inject malicious JavaScript into global site settings, which then executes when any visitor or administrator views the website—potentially compromising site security and visitor data.

Technical details

The plugin lacks capability checks on authenticated flipbook management endpoints, allowing Author-level users and above to call administrative functions without proper authorization checks (CWE-862). Attackers can delete content belonging to other users and modify administrator-only global settings by injecting JavaScript payloads that persist in the database. The vulnerability requires at least Author role authentication but exploits the broken access control to reach unintended functionality.

Affected products

  • Real3D Flipbook before 5.4

Timeline

  • 2026-09-21: disclosed
  • 2026-09-21: patched: Fixed in version 5.4

References

Related threats