CVE-2026-86842
Real3D Flipbook Lite < 5.4 - Author+ Content Deletion and Stored XSS via Global Settings Overwrite
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access and above to delete other users' flipbook content and overwrite administrator-only global settings, which can be leveraged to store JavaScript that executes in the context of any visitor or administrator viewing the site.
| Vendor | unknown |
| Product | real3d flipbook |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown real3d flipbook
Be the first to know when new unknown vulnerabilities affecting unknown real3d flipbook are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Real3D Flipbook
0 < 5.4
References
Credits
Artus KG WPScan