Unauthorized Data Access in 3D FlipBook Plugin for WordPress
CVE-2026-1314
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 April 2026
What is CVE-2026-1314?
The 3D FlipBook β PDF Embedder, PDF Flipbook Viewer, and Flipbook Image Gallery plugin for WordPress has a vulnerability that allows unauthorized users to access sensitive flipbook page metadata. This issue arises from a lack of capability checks in the send_post_pages_json() function, affecting all versions up to and including 1.16.17. As a result, unauthenticated attackers could potentially retrieve data related to draft, private, and password-protected flipbooks, posing significant risks to user privacy and content integrity.
Affected Version(s)
3D FlipBook β PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery 0 <= 1.16.17