← WordPress Vulnerabilities
WordPress security by component

3D Flipbook PDF Viewer & Embedder

3D Flipbook PDF Viewer & Embedder is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.2.

Plugin slug: pdf-embed-viewer

CVE-2026-59552: 3D Flipbook PDF Viewer permits unauthenticated server-side request forgery

3D Flipbook PDF Viewer & Embedder through 1.4.2 lets an unauthenticated attacker supply a destination that reaches an undisclosed server-side fetch operation. This can make the WordPress server send requests to attacker-selected or internal resources. The Patchstack CNA record does not disclose the route, action, URL parameter, fetch function, allowed schemes or response visibility.

PublishedJul 27, 2026
Known safe version1.4.4
Safe version
Jul 27, 2026 CVE-2026-59552
3D Flipbook PDF Viewer permits unauthenticated server-side request forgery
3D Flipbook PDF Viewer & Embedder through 1.4.2 lets an unauthenticated attacker supply a destination that reaches an undisclosed server-side fetch operation. This can make the WordPress server send requests to attacker-selected or internal resources. The Patchstack CNA record does not disclose the route, action, URL parameter, fetch function, allowed schemes or response visibility.
1.4.4
CVE7.2
NVDPending