Stored Cross-Site Scripting Vulnerability in Dear Flipbook Plugin for WordPress
CVE-2026-2569
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 March 2026
What is CVE-2026-2569?
The Dear Flipbook plugin for WordPress, which allows users to display PDF documents in a flipbook format, is susceptible to a Stored Cross-Site Scripting issue. This vulnerability arises from inadequate input sanitization and output escaping for PDF page labels. Authenticated users with Author-level permissions or higher may exploit this flaw to inject malicious scripts into PDF pages, which would be executed when other users access those compromised pages. This can lead to unauthorized actions on behalf of legitimate users, potentially compromising site integrity and user data.
Affected Version(s)
Dear Flipbook β PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer 0 <= 2.4.20