/Vulnerability Library

WordPress 3D FlipBook Plugin <= 1.16.17 - Sensitive Information Exposure

CVE-2025-58226
Verified

Description

The 3D FlipBook WordPress plugin (≤ v1.16.17) has a vulnerability where an unauthenticated AJAX action (fb3d_send_posts) exposes sensitive data. Attackers can access all flipbook posts—including password-protected content, metadata, PDF URLs, and plugin settings—without authorization.

Severity

Medium

Published Date

April 23, 2026

Template Author

pussycat0x

CVE-2025-58226.yaml
5.0Severity

CVSS Metrics

References

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/interactive-3d-flipbook-powered-physics-engine/https://patchstack.com/database/wordpress/plugin/interactive-3d-flipbook-powered-physics-engine/vulnerability/...https://plugins.svn.wordpress.org/interactive-3d-flipbook-powered-physics-engine/

Remediation Steps

Update to the latest version.