The PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pdf_source' parameter in all versions up to, and including, 2.3.32 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
We have discovered 20,005 live websites that are affected by CVE-2024-8717.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 20,005 live websites (37.30% of 3d Flipbook Dflip Lite install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 59 versions ( 89.39% of all versions) |
![]() | 5,199 websites |
![]() | 2,598 websites |
![]() | 1,389 websites |
![]() | 832 websites |
![]() | 705 websites |
![]() | 593 websites |
![]() | 473 websites |
![]() | 470 websites |
![]() | 441 websites |
![]() | 422 websites |
.com | 6,682 websites |
.org | 1,377 websites |
.de | 1,140 websites |
.it | 703 websites |
.fr | 469 websites |
.com.br | 439 websites |
.co.uk | 419 websites |
.net | 370 websites |
.nl | 362 websites |
.pl | 341 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***.***.edu | ![]() | *,*** | |
********.de | ![]() | **,*** | |
******.com | ![]() | **,*** | |
******************.org | ![]() | **,*** | |
***********.org | ![]() | **,*** | |
**********.**.uk | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
***.gr | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
**************.com | ![]() | **,*** |
FAQ