Executive brief
The picu plugin for WordPress, which is used by photographers to manage client photo galleries, contains a security flaw that allows for stored cross-site scripting. An attacker can inject malicious scripts into the website that execute when a legitimate user or administrator visits certain pages. This could lead to unauthorized actions being performed in the user's session, such as redirecting visitors to malicious sites or stealing sensitive session information.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the picu WordPress plugin (versions <= 3.5.1) due to improper neutralization of input during web page generation (CWE-79). The vulnerability allows an unauthenticated remote attacker to inject malicious scripts into the application. These scripts are stored on the server and executed in the context of a victim's browser when they interact with the affected component. Exploitation requires some level of user interaction, such as a privileged user viewing a specific page. The issue is resolved in version 3.6.1.
Affected products
- picu picu <= 3.5.1
Timeline
- 2026-05-18: other: Vulnerability reported by researcher xwii
- 2026-07-08: advisory: Patchstack published advisory and mitigation rules
- 2026-07-13: disclosed: CVE published to NVD dataset