CVE-2025-15696: Real3D Flipbook Lite < 5.4 - Author+ Stored XSS
The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any user who later opens the affected flipbook for editing, including administrators.
Affected Software
Event History
Frequently Asked Questions
Which users can exploit this issue?
Any authenticated WordPress user with the Author role or a higher-privileged role can inject malicious script through affected flipbook editor fields.
Who is at risk of having code execute in their browser?
Any user who later opens an affected flipbook in the admin editor is exposed. This includes administrators, so stored payloads can target higher-privileged accounts.
Are default site visitors affected?
The available information identifies the admin editor as the execution point. It does not indicate that scripts execute for users merely viewing a flipbook on the public site.
How can administrators identify potentially affected content?
Review flipbooks created or edited by Author-level and higher users for unexpected or suspicious content in flipbook editor fields. The issue affects versions before 5.4.