shouldiuse.io

VERDICT

Should I use picu?

picu is a photo proofing plugin for WordPress: Create a gallery, send the link to your client, automatically get notified once the selection is done. - picu.io

Depends. A reasonable fit for freelance photographers already running WordPress who need simple client picks — but only if you update promptly. Not for sensitive client work or non-WordPress sites, and independent user evidence is thin.

Confidence

Low. Based on 8 public sources; nearly all substantive evidence is security advisories — user review coverage is minimal.

Ratings

  • Value for moneyNo pricing data in reviewed sources
  • Ease of use
  • Feature depthNo feature evidence found
  • Support qualityNo user support evidence found
  • Security posture

Pricing

Not disclosed

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed

Best for

  • Freelance photographers
  • WordPress site owners
  • Quick client photo picks
  • Small studios

Not for

  • Non-WordPress sites — it's a plugin, full stop
  • Photographers delivering sensitive or commercial client work
  • Anyone wanting hosted, hands-off proofing
  • Teams needing DAM, sales, or editing features

Gotchas - check before you buy

high

Unauthenticated flaw affected versions through 3.5.1 — verify you run a patched release before sharing client links

medium

Past broken access control issue in 2.4.0 and below — old installs may remain exposed

medium

No public security page — hard to assess patch practices

Pros and cons

Pros

  • Simple flow: build gallery, share link, get notified on completion
  • Directory review highlights a streamlined client experience
  • Runs an official vulnerability disclosure program via Patchstack

Cons

  • Two CVEs: authorization bypass and cross-site scripting
  • Unauthenticated vulnerability reported in versions through 3.5.1
  • Broken access control flaw affecting version 2.4.0 and below
  • No security page on the official site

Sources & method

Analyzed 9/21/2026 - 8 sources - Repeated disclosures — one auth-bypass CVE, one XSS CVE, plus unauthenticated and access-control issues; a disclosure program exists but no security page.

official x2review x1security x5
  • CVE-2025-24590: Authorization bypass, Missing authorization flaw disclosed for picu
  • CVE-2026-57387: Cross-site scripting, Improper neutralization of input during web page generation
  • Unauthenticated vulnerability, <= 3.5.1, Wordfence lists an unauthenticated issue in picu through version 3.5.1
  • Broken access control, <= 2.4.0, Patchstack records broken access control in picu 2.4.0 and below

Key stats

  • Ease of use: 4/5

    Rating

  • Not disclosed

    Starting price

  • 8

    Sources

  • Analyzed

  • Value for money. No pricing data in reviewed sources
  • Ease of use: 4/5. Directory review cites streamlined client experience
  • Feature depth. No feature evidence found
  • Support quality. No user support evidence found
  • Security posture: 2/5. Multiple CVEs, unauthenticated flaws, no security page
  • 2 Known CVEs Auth bypass (2025), XSS (2026)
  • <= 3.5.1 Affected versions Unauthenticated issue per Wordfence
  • Not found Security page picu.io/security returned no page

Pricing

Not disclosed

Security

Repeated disclosures — one auth-bypass CVE, one XSS CVE, plus unauthenticated and access-control issues; a disclosure program exists but no security page.

  • CVE-2025-24590: Authorization bypassMissing authorization flaw disclosed for picu⁴
  • CVE-2026-57387: Cross-site scriptingImproper neutralization of input during web page generation⁵
  • Unauthenticated vulnerability, <= 3.5.1Wordfence lists an unauthenticated issue in picu through version 3.5.1⁶
  • Broken access control, <= 2.4.0Patchstack records broken access control in picu 2.4.0 and below⁷

What users say

Independent user reviews are scarce; the coverage found is a directory listing praising a streamlined client experience.

Alternatives

Compare picu with each alternative.

  • Google Drive shared album

    Free, zero-setup client selections; no plugin security risk.

Full analysis

Based on 8 public sources; nearly all substantive evidence is security advisories — user review coverage is minimal.

Handy WordPress proofing plugin for simple client picks, but repeated CVEs and thin user evidence make update discipline mandatory.

Methodology

Based on 8 public sources; nearly all substantive evidence is security advisories — user review coverage is minimal.

Sources

  1. review
  2. official
  3. official
  4. security
  5. security
  6. security
  7. security
  8. security

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.