Qiniu Uploader

Qiniu Uploader has one disclosed vulnerability in the WordSec catalog, all reported in 2014; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Qiniu Uploader has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2014.

All of these findings were reported by Prajal Kulkarni. Qiniu Uploader is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.5.0.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Qiniu Uploader vulnerabilities before they are exploited.

Most severe open issueCVSS 6.1

Qiniu Uploader <= 0.1 - Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Plugin Profile
Latestv0.1

Qiniu Uploader

franzcai

Author

franzcai

0.0(0)
0/100
Last Updated
2013-01-25 (14y ago)
Active Installs
10+
Downloads
3,386
Requires WP
2.6+
Requires PHP
0+
Tested up to
WP 3.5.0
Created
2013-01-24 (14y ago)

You can upload your image to qiniu cloud storage some code refer to the following plugin https://wordpress.org/extend/plugins/dbank-uploader/ Please report bug in https://github.com/caichicong/qiniu-uploader. Thank you. 安装这个插件之后,可以在文章编辑界面点击七牛的图标,上传文件到七牛云储存 部分代码参考了以下插件 https://wordpress.org/extend/plugins/dbank-uploader/ 请到 https://github.com/caichicong/qiniu-uploader 反馈bug. 谢谢 Prerequisite Please install curl extension for php (http://php.net/manual/en/curl.installation.php) Plugin Usage 点击富文本编辑器中的七牛图标,在弹出的窗口中点击upload选择要上传的文件,上传完毕后, 窗口将自动关闭,图片会插入到编辑器相应的位置中。 你可以在 后台管理菜单栏Media (多媒体)下的”七牛云储存”查看已经上传了的文件 todo 图片删除功能 水印添加功能

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C