USS Upyun

USS Upyun has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for USS Upyun has a vendor fix available, so running the current release closes it.

All of these findings were reported by Sandeep Kambhampati. USS Upyun is installed on roughly 30 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all USS Upyun vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2025-9629

USS Upyun <= 1.5.0 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
USS Upyun banner
Latestv1.5.1

USS Upyun

沈唁

Author

沈唁

0.0(0)
0/100
Last Updated
2026-05-27 (4mo ago)
Active Installs
30+
Downloads
5,606
Requires WP
4.6+
Requires PHP
7.0.0+
Tested up to
WP 7.0.4
Created
2020-03-28 (7y ago)

使用又拍云云存储USS作为附件存储空间。(This is a plugin that uses UPYUN Storage Service for attachments remote saving.) 依赖又拍云云存储USS服务:https://www.upyun.com/products/file-storage 插件特点 可配置是否上传缩略图和是否保留本地备份 本地删除可同步删除又拍云云存储USS中的文件 支持又拍云云存储USS绑定的个性域名 支持替换数据库中旧的资源链接地址 支持又拍云云存储USS完整地域使用 支持同步历史附件到又拍云云存储USS 支持上传时自动重命名文件(MD5或时间戳+随机数两种方式) 支持设置图片处理 支持多站点 插件更多详细介绍和安装:https://github.com/sy-records/upyun-uss-wordpress 其他插件 腾讯云COS:GitHub,WordPress Plugins 华为云OBS:GitHub,WordPress Plugins 七牛云KODO:GitHub,WordPress Plugins 阿里云OSS:GitHub,WordPress Plugins 作者博客 沈唁志 QQ交流群:887595381

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C