Sceawere

Vulnerability Detail

CVE-2026-74007UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Sensitive Data Exposure in 3D FlipBook

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
iberezansky
Product
3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery
Attack Type
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-18T15:17:09.300Z",
  "pubdate": "2026-08-18T15:17:09.300Z",
  "executiveSummary": "An unauthenticated sensitive data exposure vulnerability has been identified in the 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery plugin affecting versions 1.16.20 and prior. This security flaw allows unauthenticated remote attackers to access restricted or sensitive information managed by the plugin without requiring valid credentials or session tokens.\nThe vulnerability poses a significant risk to confidentiality, potentially exposing proprietary documents, media galleries, or internal configurations hosted within the flipbook viewer components. The attack requires network connectivity to the vulnerable WordPress installation and exploits improper access controls enforced by the application layer.\nSuccessful exploitation allows unauthorized third parties to harvest sensitive data directly from the server, bypassing intended authorization boundaries. Organizations utilizing the affected software versions face potential data breaches and unauthorized information disclosure risks.\nImmediate remediation requires updating the 3D FlipBook plugin beyond version 1.16.20 once a patched release is made available by the vendor, alongside implementing strict access controls and monitoring application logs for suspicious request patterns targeting plugin endpoints.",
  "technicalDetails": "The vulnerability resides in the 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress, specifically impacting versions 1.16.20 and earlier. The root cause stems from insufficient access control enforcement and the absence of proper authentication checks on sensitive endpoints or AJAX handlers responsible for retrieving flipbook content and associated metadata.\nFrom an authentication and privilege perspective, the vulnerability is fully exploitable by unauthenticated remote attackers over the network. No prior privileges, administrative roles, or valid user sessions are required to interact with the vulnerable functions. The affected component fails to validate whether the requesting entity possesses the necessary permissions to view the underlying resources.\nThe exploitation method involves sending crafted HTTP requests directly to the exposed plugin endpoints or AJAX actions responsible for data retrieval. Because the application processes these requests without verifying authorization state, it responds by returning the sensitive data payload containing PDF files, images, or configuration parameters associated with the flipbook instances.\nThe attack flow proceeds as follows: First, the attacker identifies the presence of the vulnerable 3D FlipBook plugin on the target WordPress site. Second, the attacker formulates an HTTP request targeting the insecure function or endpoint responsible for rendering or fetching flipbook assets. Third, the server processes the unauthenticated request and returns the requested sensitive files or data streams. Finally, the attacker ingests and stores the harvested data, resulting in a complete confidentiality breach of the affected flipbook repositories.\nPost-exploitation impact is strictly centered around unauthorized data exposure. Attackers can systematically enumerate and download restricted PDF documents and image galleries, potentially leading to the leakage of intellectual property, copyrighted material, or internal organizational documents stored within the plugin's file structure."
}
CVE-2026-74007: Unauthenticated Sensitive Data Exposure in 3D FlipBook (MEDIUM Severity, CVSS: 5.3) - Sceawere