CVE-2026-104395: WordPress picu plugin <= 3.10.1 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in picu <= 3.10.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress picu pluginto a version that resolves this vulnerability.Fixed in 3.10.2
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is described as unauthenticated, so an attacker does not need a WordPress account or plugin-specific privileges to attempt exploitation. Exploitation still requires user interaction, as indicated by the UI:R vector.
What versions are affected?
picu plugin versions up to and including 3.10.1 are identified as affected. The provided information does not identify a fixed version.
What is the likely impact if exploitation succeeds?
The issue is cross-site scripting, with the supplied vector indicating low confidentiality, integrity, and availability impact. Its scope is changed, meaning effects may extend beyond the vulnerable component's own security authority.