Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-15758— 3D FlipBook <= 1.16.20 - Unauthenticated Sensitive Information Exposure in 'id' Parameter

Quick assessment

Affected
iberezansky 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件“3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery”在包括 1.16.20 在内的所有版本中,通过 参数存在敏感信息泄露漏洞。该漏洞允许未认证的攻击者提取受密码保护的翻书(flipbook)的完整元数据负载,其中包括标题、大纲、属性(props)以及包含底层 PDF 文件直接 URL 的序列化数据块,从而绕过 WordPress 文章密码保护的保密性。此外,未认证的 AJAX 操作可用于预先枚举翻书

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1039 · Data from Network Shared Drive
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-15758

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
3D FlipBook <= 1.16.20 - Unauthenticated Sensitive Information Exposure in 'id' Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including the full metadata payload of password-protected flipbooks — including title, outline, props, and the serialized data blob containing the underlying PDF file's direct URL — bypassing WordPress post-password confidentiality. Flipbook post IDs can be pre-enumerated via the also-unauthenticated fb3d_send_posts AJAX action, requiring no prior knowledge to target specific flipbooks.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
iberezansky 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery 0 ~ 1.16.20 -

II. Public POCs for CVE-2026-15758

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15758

登录查看更多情报信息。

Patches & Fixes for CVE-2026-15758 (2)

Security Blog Posts for CVE-2026-15758 (1)

Vendor Pages for CVE-2026-15758 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-15758

No comments yet


Leave a comment