WordPress 3D FlipBook <= 1.16.17 - Information Disclosure
CVE-2026-1314
Verified
Description
WordPress 3D FlipBook - PDF Flipbook Viewer, Flipbook Image Gallery plugin versions <= 1.16.17 contain a missing authorization vulnerability in multiple AJAX endpoints. The fb3d_send_posts_in, fb3d_send_post_pages, fb3d_send_posts_in_pages, fb3d_send_posts_in_first_page, and fb3d_send_post_first_page handlers are registered with wp_ajax_nopriv hooks but fail to verify the post status of requested flipbook entries. This allows unauthenticated attackers to retrieve full metadata, PDF URLs, and configuration data of private, draft, and password-protected flipbook posts.
Severity
Medium
CVSS Score
5.3
Exploit Probability
1%
Affected Product
interactive_3d_flipbook
Published Date
April 15, 2026
Template Author
theamanrawat
CVE-2026-1314.yaml
5.3Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2026-1314
CWE ID:
cwe-862
References
https://patchstack.com/database/wordpress/plugin/interactive-3d-flipbook-powered-physics-engine/vulnerability/wordpress-3d-flipbook-pdf-embedder-pdf-flipbook-viewer-flipbook-image-gallery-plugin-1-16-17-missing-authorization-to-unauthenticated-private-draft-flipbook-data-exposure-vulnerabilityhttps://nvd.nist.gov/vuln/detail/CVE-2026-1314
Remediation Steps
Upgrade the 3D FlipBook - PDF Flipbook Viewer, Flipbook Image Gallery plugin to version 1.16.18 or later.