KODO Qiniu

KODO Qiniu has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for KODO Qiniu has a vendor fix available, so running the current release closes it.

KODO Qiniu is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all KODO Qiniu vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3

KODO Qiniu <= 1.5.0 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
KODO Qiniu banner
Latestv1.5.10

KODO Qiniu

沈唁

Author

沈唁

5.0(2)
100/100
Last Updated
2026-05-27 (4mo ago)
Active Installs
300+
Downloads
15,100
Requires WP
4.6+
Requires PHP
7.1+
Tested up to
WP 7.0.4
Created
2020-03-27 (7y ago)

使用七牛云海量存储系统 KODO 作为附件存储空间。(This is a plugin that uses Qiniu Cloud KODO for attachments remote saving.) 依赖七牛云海量存储系统 KODO 服务:https://www.qiniu.com/products/kodo 使用说明:https://developer.qiniu.com/kodo?ref=www.qq52o.me 插件特点 可配置是否上传缩略图和是否保留本地备份 本地删除可同步删除七牛云海量存储系统 KODO 中的文件 支持七牛云海量存储系统 KODO 绑定的个性域名 支持替换数据库中旧的资源链接地址 支持七牛云海量存储系统 KODO 完整地域使用 支持同步历史附件到七牛云海量存储系统 KODO 支持七牛云图片样式 支持七牛云原图保护 支持媒体库编辑 支持上传文件自动重命名 支持图片裁剪编辑等操作后的上传 支持多站点 支持使用 wp-cli 命令上传/删除文件 插件更多详细介绍和安装:https://github.com/sy-records/qiniu-kodo-wordpress 其他插件 腾讯云 COS:GitHub,WordPress Plugins 华为云 OBS:GitHub,WordPress Plugins 阿里云 OSS:GitHub,WordPress Plugins 又拍云 USS:GitHub,WordPress Plugins 作者博客 沈唁志 QQ 交流群:887595381

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C