EIP-2026-113998

PRE-CVE

WordPress Plugin Real3D FlipBook - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113998. PoCs published by Mukarram Khalid.

AI-analyzed exploit summary This exploit targets multiple vulnerabilities in the Real3D FlipBook WordPress plugin, including arbitrary file deletion, file upload, and XSS. It demonstrates functional exploit code that interacts with vulnerable endpoints to delete files, upload a malicious image, and trigger XSS.

Description

WordPress Plugin Real3D FlipBook - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by Mukarram Khalid · pythonwebappsphp
https://www.exploit-db.com/exploits/40055

This exploit targets multiple vulnerabilities in the Real3D FlipBook WordPress plugin, including arbitrary file deletion, file upload, and XSS. It demonstrates functional exploit code that interacts with vulnerable endpoints to delete files, upload a malicious image, and trigger XSS.

Classification
Working Poc 95%
Attack Type
Xss | Other
Complexity
Moderate
Reliability
Reliable
Target: Real3D FlipBook WordPress Plugin
No auth needed
Prerequisites: Python 3.4.x or higher · Requests module · Target URL with vulnerable plugin
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026