OSS Aliyun
OSS Aliyun has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 9.1, and the most serious one scores 9.1 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is SQL Injection, behind 1 of the records (100%).
The one issue recorded for OSS Aliyun has a vendor fix available, so running the current release closes it.
All of these findings were reported by Majed Refaea. OSS Aliyun is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-30494OSS Aliyun <= 1.4.10 - Authenticated (Administrator+) SQL Injection
Read the full analysisVulnerability Records

OSS Aliyun
Author
沈唁
使用阿里云对象存储 OSS 作为附件存储空间。(This is a plugin that uses Aliyun Object Storage Service for attachments remote saving.) 依赖阿里云 OSS 服务:https://www.aliyun.com/product/oss 插件特点 可配置是否上传缩略图和是否保留本地备份 本地删除可同步删除阿里云对象存储 OSS 中的文件 支持阿里云对象存储 OSS 绑定的用户域名 支持替换数据库中旧的资源链接地址 支持阿里云对象存储 OSS 完整地域使用 支持同步历史附件到阿里云对象存储 OSS 支持阿里云 OSS 图片处理 支持上传文件自动重命名 支持使用 ECS 的 RAM 操作 支持原图保护 支持 wp-cli 命令上传/删除文件 支持多站点 支持图片裁剪编辑等操作后的上传 插件更多详细介绍和安装:https://github.com/sy-records/aliyun-oss-wordpress 其他插件 腾讯云 COS:GitHub,WordPress Plugins 华为云 OBS:GitHub,WordPress Plugins 七牛云 KODO:GitHub,WordPress Plugins 又拍云 USS:GitHub,WordPress Plugins 作者博客 沈唁志 欢迎加入沈唁的 WordPress 云存储全家桶 QQ 交流群:887595381
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C