KODO Qiniu
KODO Qiniu has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for KODO Qiniu has a vendor fix available, so running the current release closes it.
KODO Qiniu is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
KODO Qiniu <= 1.5.0 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

KODO Qiniu
Author
沈唁
使用七牛云海量存储系统 KODO 作为附件存储空间。(This is a plugin that uses Qiniu Cloud KODO for attachments remote saving.) 依赖七牛云海量存储系统 KODO 服务:https://www.qiniu.com/products/kodo 使用说明:https://developer.qiniu.com/kodo?ref=www.qq52o.me 插件特点 可配置是否上传缩略图和是否保留本地备份 本地删除可同步删除七牛云海量存储系统 KODO 中的文件 支持七牛云海量存储系统 KODO 绑定的个性域名 支持替换数据库中旧的资源链接地址 支持七牛云海量存储系统 KODO 完整地域使用 支持同步历史附件到七牛云海量存储系统 KODO 支持七牛云图片样式 支持七牛云原图保护 支持媒体库编辑 支持上传文件自动重命名 支持图片裁剪编辑等操作后的上传 支持多站点 支持使用 wp-cli 命令上传/删除文件 插件更多详细介绍和安装:https://github.com/sy-records/qiniu-kodo-wordpress 其他插件 腾讯云 COS:GitHub,WordPress Plugins 华为云 OBS:GitHub,WordPress Plugins 阿里云 OSS:GitHub,WordPress Plugins 又拍云 USS:GitHub,WordPress Plugins 作者博客 沈唁志 QQ 交流群:887595381
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C