CVE-2026-8625
- EPSS 0.21%
- Veröffentlicht 05.09.2026 05:30:55
- Zuletzt bearbeitet 08.09.2026 13:12:58
The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (Custom HTML block inner HTML)' parameter in all versions up to, and including, 2.4.30 due to...
CVE-2026-8623
- EPSS 0.21%
- Veröffentlicht 05.09.2026 05:30:53
- Zuletzt bearbeitet 08.09.2026 13:12:58
The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (class attribute of .dvcss element)' parameter in all versions up to, and including, 2.4.30 d...
CVE-2026-49047
- EPSS 0.16%
- Veröffentlicht 27.05.2026 15:16:33
- Zuletzt bearbeitet 27.05.2026 19:43:00
Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DearFlip: from n/a through 2.4.27.
CVE-2024-29807
- EPSS 0.34%
- Veröffentlicht 27.03.2024 13:15:53
- Zuletzt bearbeitet 28.04.2026 19:23:49
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DearHive DearFlip allows Stored XSS.This issue affects DearFlip: from n/a through 2.2.26.
CVE-2021-24732
- EPSS 0.65%
- Veröffentlicht 18.10.2021 14:15:09
- Zuletzt bearbeitet 21.11.2024 05:53:39
The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.10 does not escape the class attribute of its shortcode before outputting it back in an attribute, which could allow users with a role as low as Contributor to perform Sto...