Stored Cross-Site Scripting Vulnerability in Dear Flipbook Plugin for WordPress
CVE-2026-8623
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 September 2026
What is CVE-2026-8623?
The Dear Flipbook plugin for WordPress contains a stored cross-site scripting vulnerability due to inadequate input sanitization and output escaping in the 'post_content' parameter associated with the .dvcss class. Authenticated users with contributor-level access and higher can exploit this vulnerability by injecting malicious scripts into pages, which execute when accessed by other users. The attack vector involves embedding a Base64-encoded JSON object within a CSS class name on a Custom HTML block. The frontend function parseCSSElements() decodes the payload client-side, allowing the embedded script to render as raw HTML without any sanitization checks, leading to potential compromise of user interactions.
Affected Version(s)
DearFlip β PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer 0 <= 2.4.30