The Dear Flipbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (Custom HTML block inner HTML)' parameter in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access to inject arbitrary web scripts, which can execute on pages accessed by use [truncated]
The Dear Flipbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (class attribute of .dvcss element)' parameter in all versions up to, and including, 2.4.30. Authenticated attackers with contributor-level access and above can inject arbitrary web scripts, which execute when a user accesses an injected page. This vulnerability allows for potential malicious script i [truncated]
A Missing Authorization vulnerability in the DearFlip WordPress plugin allows authenticated users with low privileges to exploit incorrectly configured access control security levels. The vulnerability affects all versions from n/a through 2.4.27. The issue was disclosed on 2026-05-27 and carries a CVSS 3.1 score of 4.3 (Medium severity), indicating limited impact on confidentiality with no impact on inte [truncated]