Stored Cross-Site Scripting Vulnerability in Dear Flipbook Plugin for WordPress
CVE-2026-2569
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 March 2026
What is CVE-2026-2569?
The Dear Flipbook plugin for WordPress, which allows users to display PDF documents in a flipbook format, is susceptible to a Stored Cross-Site Scripting issue. This vulnerability arises from inadequate input sanitization and output escaping for PDF page labels. Authenticated users with Author-level permissions or higher may exploit this flaw to inject malicious scripts into PDF pages, which would be executed when other users access those compromised pages. This can lead to unauthorized actions on behalf of legitimate users, potentially compromising site integrity and user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Dear Flipbook β PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer * <= 2.4.20
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved