S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Apr 23, 2026

CVE-2025-58226 Scanner

CVE-2025-58226 Scanner - Information Disclosure vulnerability in WordPress 3D FlipBook Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-58226
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

Insertion of Sensitive Information Into Sent Data vulnerability in iberezansky 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery interactive-3d-flipbook-powered-physics-engine allows Retrieve Embedded Sensitive Data.This issue affects 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery: from n/a through <= 1.16.16.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
3D FlipBook – PDF Flipbook Viewer, Flipbook Image Galleryby iberezansky
0
Updated Aug 22, 2026View on NVD →
Detail

The WordPress 3D FlipBook Plugin is widely used by website administrators to enhance their websites with interactive 3D flipbooks. This plugin is particularly popular among online publishers, educational institutions, and digital magazines to create engaging flipbook content. It helps to present documents in a manner that mimics the physical experience of flipping through a book. However, due to its integration with WordPress, it can pose a security risk if vulnerabilities like information disclosure are present. This scanner tests this particular vulnerability, helping prevent potentially unauthorized data access through this popular WordPress plugin.

The vulnerability identified in this scanner highlights a significant security concern with the WordPress 3D FlipBook Plugin. It specifically involves exposing sensitive information through an unauthenticated AJAX action known as 'fb3d_send_posts'. Such a vulnerability may allow attackers to access various sensitive data, including password-protected content and related metadata, without proper authorization. Understanding this vulnerability is crucial for administrators relying on this plugin to safeguard their content and user privacy.

The vulnerability revolves around the exposure of all flipbook posts, including sensitive data such as PDF URLs and plugin settings. The exploitable endpoint, '/wp-admin/admin-ajax.php?action=fb3d_send_posts', is accessible without authentication, allowing attackers to retrieve data via direct requests. Additionally, the plugin settings, often containing sensitive information, further compound the risk when disclosed to unauthorized users. Countermeasures should be implemented to mitigate this potential security breach, particularly for sites highly reliant on the WordPress platform.

When exploited, this vulnerability can lead to unauthorized access to sensitive information, undermining user privacy and potentially leading to data leakage. This exposure may result in severe repercussions, such as identity theft if the disclosed data includes personal user information. Organizations using this plugin may face legal challenges for failing to protect user data, impacting their reputation and user trust. It is imperative for affected parties to promptly address and rectify such vulnerabilities to mitigate potential damages.

REFERENCES

Solution Advice
  • Update the WordPress 3D FlipBook Plugin to the latest version to patch the vulnerability.
  • Implement stringent access controls to ensure sensitive data is not exposed unauthorizedly.
  • Regularly audit the website's security configuration to identify and mitigate potential vulnerabilities.
  • Review and limit the use of plugins that are not actively maintained or updated by developers.
  • Enable logging and monitoring to detect any unauthorized access attempts to the plugin data.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.