Security Fixes in picu 3.8.1 & picu Pro 2.9.1

A few days ago a customer reported an issue where, under certain conditions, picu could expose the titles and URLs of collections sent through picu. Because collection titles themselves could include real names or even addresses, those alone can be considered private information and should only ever be accessible to your clients.

What happened, exactly?

WordPress generates archive listings for many things by default, which we disable for picu collections in many places, but in one case we failed to do so. This meant that someone could potentially access a list with the titles and URLs of your proofing collections. And if those were not password protected, they could access the client view of those collections as well.

The password protection or authentication itself was never affected by this nor was your WordPress system or the data entered into picu by your clients being compromised. And if you used password protection on your collections, the content of those collections was still protected by that password, but the title and URL of the collection could be seen.

What we did

We take these kinds of reports very serious, and issued a patched bugfix release within hours of this issue being brought to our attention. Also, we searched for and found one other spot in picu Pro with a similar (though less serious) problem and fixed that as well. On top of that, we started to do a full security audit of our codebase, just to make sure and to keep your proofing collections as secure as they can be.

What you should do

If you are using picu and/or picu Pro, you should update to the latest versions as soon as you can: picu 3.8.1 and picu Pro 2.9.1 respectively. If you have automatic updates enabled, you may already be on those versions, but it’s worth double-checking under Plugins in your WordPress admin either way and trigger the update manually, if necessary.

Reporting future issues

First of all, thanks again to the customer who brought this to our attention, for disclosing it responsibly and directly to us.

If you ever find a security issue yourself (or think you did), please don’t post about it publicly and don’t test it against sites you don’t own. Instead always report it responsibly, either directly to us or through the Patchstack Vulnerability Disclosure Program. Their team helps with verification and CVE assignment, and makes sure it reaches us.

We will post some more information on our processes to keep picu and your collections as safe as we possibly can. In the meantime, please take the time to check your sites and update to the newest version.

If you have any questions about this, please don’t hesitate to get in touch directly and we’re happy to answer any questions.

Related Posts

These posts could interest you as well, read on to get the full picture.