CVE-2026-39760: WordPress Real 3D FlipBook plugin <= 5.5 - Cross Site Scripting (XSS) vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.
Affected Software
1 affected component
WordPress Real 3D FlipBook<=5.5
Event History
Oct 6, 2026
CVE Published
via MITRE·05:14 AM
Data Sourced
via MITRE·05:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. Exploitation does require user interaction.
2
What is the potential impact?
The issue is rated high severity with a CVSS score of 7.1. Its vector indicates low impact to confidentiality, integrity, and availability, and that successful exploitation can affect a scope beyond the vulnerable component.
3
Which plugin versions are affected?
Real 3D FlipBook versions 5.5 and earlier are affected according to the available data.