CVE-2026-59552
Received Received - Intake

Unauthenticated SSRF in 3D Flipbook PDF Viewer & Embedder

Vulnerability report for CVE-2026-59552, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: Patchstack

Description

Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
3d_flipbook_pdf_viewer 3d_flipbook_pdf_viewer 1.4.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-59552 is an unauthenticated Server Side Request Forgery (SSRF) vulnerability in the 3D Flipbook PDF Viewer & Embedder WordPress plugin versions 1.4.2 and below. It allows attackers to make the website send requests to arbitrary domains without authentication.

Detection Guidance

To detect this SSRF vulnerability, monitor network traffic for unusual outbound requests from your WordPress server, especially to internal or unexpected domains. Check server logs for requests originating from the 3D Flipbook plugin. Use tools like tcpdump or Wireshark to capture and analyze traffic patterns.

Impact Analysis

An attacker could exploit this to access sensitive information from other services running on the system. This could lead to data breaches, unauthorized access to internal systems, or further attacks on the server.

Compliance Impact

This vulnerability could lead to unauthorized data access, potentially violating GDPR (data protection) and HIPAA (health information privacy) by exposing sensitive user data.

Mitigation Strategies

Immediately update the 3D Flipbook PDF Viewer & Embedder plugin to version 1.4.4 or later. If updating is not possible, apply mitigation rules provided by Patchstack or disable the plugin until patched. Restrict outbound server requests and monitor for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59552. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart