Sensitive Information Exposure in 3D FlipBook Plugin for WordPress
CVE-2026-15758
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 September 2026
What is CVE-2026-15758?
The 3D FlipBook plugin for WordPress exposes sensitive information due to an insecure handling of the 'id' parameter. Attackers can exploit this vulnerability to retrieve sensitive metadata from password-protected flipbooks, including titles, outlines, and URLs of the underlying PDFs. The vulnerability can be exploited anonymously, allowing attackers to pre-enumerate flipbook post IDs and bypass existing protections, making confidential information accessible without authentication.
Affected Version(s)
3D FlipBook β PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery 0 <= 1.16.20