cleantalk
Vulnerabilities and Security Researches

3D FlipBook – PDF Flipbook WordPress, CVE-2022-0423

CVE, Research URL

CVE-2022-0423

Published on
Mar 22, 2022
Research Description
The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads in all pages with a 3d flipbook.
Affected versions
max 1.12.1.
Status
vulnerable