CVE-2025-15696
6.8 MEDIUMPublished 2026-09-23 · Updated 2026-09-23
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any user who later opens the affected flipbook for editing, including administrators.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-79
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-13533PoC
- MEDIUMCVE-2025-14814
- LOWCVE-2025-15677
- LOWCVE-2025-15698
- MEDIUMCVE-2025-36147
- HIGHCVE-2025-61682PoC
- MEDIUMCVE-2025-71419PoC
- UNSCOREDCVE-2026-100172PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.