Arbitrary Web Script Injection in Real3D Flipbook Plugin for WordPress
CVE-2025-15696
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 23 September 2026
Badges
What is CVE-2025-15696?
The Real3D Flipbook plugin for WordPress versions before 5.4 is susceptible to an arbitrary web script injection vulnerability. This occurs due to inadequate sanitization and escaping of several editor fields in the admin interface. As a result, users with Author permissions and higher can insert malicious scripts into the flipbook editor. These scripts will execute in the browser of any user who accesses the affected flipbook for editing, including those with administrative rights, compromising the security of the site and its users.
Affected Version(s)
Real3D Flipbook 0 < 5.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.