The 3D FlipBook WordPress plugin (≤ v1.16.17) has a vulnerability where an unauthenticated AJAX action (fb3d_send_posts) exposes sensitive data. Attackers can access all flipbook posts—including password-protected content, metadata, PDF URLs, and plugin settings—without authorization.
id: CVE-2025-58226
info:
name: WordPress 3D FlipBook Plugin <= 1.16.17 - Sensitive Information Ex
...