Sync QCloud COS

Sync QCloud COS has one disclosed vulnerability in the WordSec catalog, all reported in 2022; it is fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 5.5 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Sync QCloud COS has a vendor fix available, so running the current release closes it.

All of these findings were reported by fuzzyap1. Sync QCloud COS is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
5.5/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Sync QCloud COS vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.5CVE-2022-0659

Sync QCloud COS Plugin < 2.0.1 - Authenticated (Admin+) Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Sync QCloud COS banner
Latestv2.6.7

Sync QCloud COS

沈唁

Author

沈唁

5.0(6)
100/100
Last Updated
2026-05-27 (4mo ago)
Active Installs
600+
Downloads
25,336
Requires WP
4.6+
Requires PHP
7.2+
Tested up to
WP 7.0.4
Created
2020-01-16 (7y ago)

使用腾讯云对象存储服务 COS 作为附件存储空间。(Using Tencent Cloud Object Storage Service COS as Attachment Storage Space.) 依赖腾讯云 COS 服务:https://cloud.tencent.com/product/cos 使用说明:https://cloud.tencent.com/product/cos/details 插件特点 可配置是否上传缩略图和是否保留本地备份 本地删除可同步删除腾讯云对象存储 COS 中的文件 支持腾讯云对象存储 COS 绑定的个性域名 支持替换数据库中旧的资源链接地址 支持北京、上海、广州、香港、法兰克福等完整地域使用 支持同步历史附件到 COS 支持验证桶名是否填写正确 支持腾讯云数据万象 CI 图片处理 支持上传文件自动重命名 支持媒体库编辑 支持腾讯云数据万象图片极智压缩 支持文件预览 支持文本内容审核 支持原图保护 支持数据监控 支持使用 wp-cli 命令上传/删除文件 支持上传文件到存储桶子目录 支持多站点 插件更多详细介绍和安装:https://github.com/sy-records/sync-qcloud-cos 作者博客 沈唁志 欢迎加入沈唁的 WordPress 云存储全家桶 QQ 交流群:887595381

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C