WordPress security by component
DearFlip
Plugin description
DearFlip is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published May 27, 2026; the highest CVE/CNA score is 6.5.
Plugin slug:
3d-flipbook-dflip-liteLatest vulnerability
CVE-2026-49047: DearFlip: A security weakness
DearFlip is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.4.27.
| Safe version |
|
||
|---|---|---|---|
| May 27, 2026 |
CVE-2026-49047
DearFlip: A security weakness
DearFlip is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.4.27.
|
> 2.4.27 |
CVE4.3
NVDPending
|
| Jul 01, 2025 |
CVE-2025-5314
Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer: Cross-site scripting
Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Oct 24, 2024 |
CVE-2024-8717
PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip: Cross-site scripting
PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Mar 27, 2024 |
CVE-2024-29807
DearFlip: Cross-site scripting
DearFlip is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Feb 03, 2024 |
CVE-2024-0895
PDF Flipbook, 3D Flipbook – DearFlip: Cross-site scripting
PDF Flipbook, 3D Flipbook – DearFlip is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|