Medium 4.3 Unfixed
2026-05-27≤ 2.4.28
CVE-2026-49047
Minimum safe version
2.4.27
Update to 2.4.27 or later to address 8 fixable vulnerabilities
CVE-2026-49047
Dear Flipbook <= 2.4.20 - Authenticated (Auhtor+) Stored Cross-Site Scripting via PDF Page Labels
Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer <= 2.3.65 - DOM-Based Reflected Cross-Site Scripting via 'pdf-source'
CVE-2024-11830
CVE-2024-8717
WordPress DearFlip Plugin <= 2.2.55 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-29807
CVE-2024-0895
CVE-2021-24732