Stored Cross-Site Scripting Vulnerability in Dear Flipbook Plugin for WordPress
CVE-2026-2569

6.4MEDIUM

What is CVE-2026-2569?

The Dear Flipbook plugin for WordPress, which allows users to display PDF documents in a flipbook format, is susceptible to a Stored Cross-Site Scripting issue. This vulnerability arises from inadequate input sanitization and output escaping for PDF page labels. Authenticated users with Author-level permissions or higher may exploit this flaw to inject malicious scripts into PDF pages, which would be executed when other users access those compromised pages. This can lead to unauthorized actions on behalf of legitimate users, potentially compromising site integrity and user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer * <= 2.4.20

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Drew Webber
.