Impact
The picu plugin for WordPress has an improper neutralization of input during web page generation, leading to a stored cross‑site scripting flaw. Data entered by users is persisted by the plugin and later rendered in other visitors’ browsers without proper filtering. This can allow an attacker to inject and execute malicious script code in the context of another user’s browser session.
Affected Systems
All releases of the picu WordPress plugin up to and including version 3.5.1 are affected. The plugin is distributed through the official WordPress plugin repository and is identified by the CNA vendor/product name picu:picu.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, which is considered high severity. The EPSS score is less than 1%, indicating a very low likelihood of exploitation currently. The vulnerability is not listed in CISA’s KEV catalog and no public exploits are known. The most probable attack vector involves user‑submitted data that is stored by the plugin and later rendered without sanitization, thereby enabling stored XSS.
OpenCVE Enrichment