CVE-2025-5314

Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer <= 2.3.65 - DOM-Based Reflected Cross-Site Scripting via 'pdf-source'

The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scripting via the ‘pdf-source’ parameter in all versions up to, and including, 2.3.65 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.


We have discovered 57,267 live websites that are affected by CVE-2025-5314.

Run a Free Instant Scan




Affected Software

Product  3d Flipbook Dflip Lite
Category Wordpress Plugins
Vulnerable Domains57,267 live websites (100% of 3d Flipbook Dflip Lite install base)
Vulnerable Versions
  • from 0 through 2.3.65
Vulnerable Versions Count60 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 1, 2025
  • Updated - Jul 1, 2025

Credits

  • Martin Herancourt (finder)

Website Distribution by Country

Number of websites using CVE-2025-5314
United States17,292 websites



Germany8,140 websites
France3,667 websites
Italy3,164 websites
GB2,192 websites
Netherlands1,581 websites
Cyprus1,375 websites
Spain1,196 websites
Poland1,025 websites
Switzerland1,021 websites

Website Distribution by TLD

Number of websites using CVE-2025-5314
.com18,300 websites
.org5,279 websites
.de4,202 websites
.it2,543 websites
.nl1,698 websites
.fr1,508 websites
.co.uk1,476 websites
.net1,033 websites
.com.br918 websites
.at784 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-5314

Top websites that are affected by CVE-2025-5314. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.edu United States*,***
********.de Germany**,***
******.com United States**,***
**************.org United States**,***
**********.org United States**,***
***********.fr France**,***
******.com United States**,***
*****.org United States**,***
****************.org United States**,***
***.***.***.au Australia**,***
See full domain list

FAQ

CVE-2025-5314 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in 3d Flipbook Dflip Lite
A total of 57,267 websites have been identified as vulnerable to CVE-2025-5314, based on global website indexing conducted by WebTechSurvey.
The 3d Flipbook Dflip Lite is affected by the CVE-2025-5314 vulnerability.
3d Flipbook Dflip Lite versions up to and including 2.3.65 are vulnerable to CVE-2025-5314.