CVE-2026-15758
Received Received - Intake

Sensitive Information Exposure in 3D FlipBook WordPress Plugin

Vulnerability report for CVE-2026-15758, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: Wordfence

Description

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including the full metadata payload of password-protected flipbooks β€” including title, outline, props, and the serialized data blob containing the underlying PDF file's direct URL β€” bypassing WordPress post-password confidentiality. Flipbook post IDs can be pre-enumerated via the also-unauthenticated fb3d_send_posts AJAX action, requiring no prior knowledge to target specific flipbooks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp3d 3d_flipbook to 1.16.20 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows unauthenticated attackers to access sensitive data from WordPress flipbook plugins by exploiting the 'id' parameter. It exposes metadata of password-protected flipbooks, including titles, outlines, and PDF URLs, bypassing confidentiality controls.

Detection Guidance

To detect this vulnerability, check WordPress sites using the 3D FlipBook plugin versions up to 1.16.20. Look for unauthorized access attempts to the 'id' parameter or unusual AJAX requests to 'fb3d_send_posts'. Review server logs for suspicious queries targeting flipbook post IDs.

Impact Analysis

Attackers could extract sensitive information like PDF URLs and metadata without authentication. This may lead to unauthorized access to protected content or further exploitation of the system.

Mitigation Strategies

Immediately update the 3D FlipBook plugin to the latest version beyond 1.16.20. If an update is unavailable, consider disabling or removing the plugin. Implement strict access controls for WordPress AJAX endpoints and monitor for unauthorized data exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15758. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart