WordPress 插件“3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery”在包括 1.16.20 在内的所有版本中,通过 参数存在敏感信息泄露漏洞。该漏洞允许未认证的攻击者提取受密码保护的翻书(flipbook)的完整元数据负载,其中包括标题、大纲、属性(props)以及包含底层 PDF 文件直接 URL 的序列化数据块,从而绕过 WordPress 文章密码保护的保密性。此外,未认证的 AJAX 操作可用于预先枚举翻书
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| iberezansky | 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery | 0 ~ 1.16.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet