Sync QCloud COS
Sync QCloud COS has one disclosed vulnerability in the WordSec catalog, all reported in 2022; it is fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 5.5 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Sync QCloud COS has a vendor fix available, so running the current release closes it.
All of these findings were reported by fuzzyap1. Sync QCloud COS is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2022-0659Sync QCloud COS Plugin < 2.0.1 - Authenticated (Admin+) Cross-Site Scripting
Read the full analysisVulnerability Records

Sync QCloud COS
Author
沈唁
使用腾讯云对象存储服务 COS 作为附件存储空间。(Using Tencent Cloud Object Storage Service COS as Attachment Storage Space.) 依赖腾讯云 COS 服务:https://cloud.tencent.com/product/cos 使用说明:https://cloud.tencent.com/product/cos/details 插件特点 可配置是否上传缩略图和是否保留本地备份 本地删除可同步删除腾讯云对象存储 COS 中的文件 支持腾讯云对象存储 COS 绑定的个性域名 支持替换数据库中旧的资源链接地址 支持北京、上海、广州、香港、法兰克福等完整地域使用 支持同步历史附件到 COS 支持验证桶名是否填写正确 支持腾讯云数据万象 CI 图片处理 支持上传文件自动重命名 支持媒体库编辑 支持腾讯云数据万象图片极智压缩 支持文件预览 支持文本内容审核 支持原图保护 支持数据监控 支持使用 wp-cli 命令上传/删除文件 支持上传文件到存储桶子目录 支持多站点 插件更多详细介绍和安装:https://github.com/sy-records/sync-qcloud-cos 作者博客 沈唁志 欢迎加入沈唁的 WordPress 云存储全家桶 QQ 交流群:887595381
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C