USS Upyun
USS Upyun has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for USS Upyun has a vendor fix available, so running the current release closes it.
All of these findings were reported by Sandeep Kambhampati. USS Upyun is installed on roughly 30 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-9629USS Upyun <= 1.5.0 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

USS Upyun
Author
沈唁
使用又拍云云存储USS作为附件存储空间。(This is a plugin that uses UPYUN Storage Service for attachments remote saving.) 依赖又拍云云存储USS服务:https://www.upyun.com/products/file-storage 插件特点 可配置是否上传缩略图和是否保留本地备份 本地删除可同步删除又拍云云存储USS中的文件 支持又拍云云存储USS绑定的个性域名 支持替换数据库中旧的资源链接地址 支持又拍云云存储USS完整地域使用 支持同步历史附件到又拍云云存储USS 支持上传时自动重命名文件(MD5或时间戳+随机数两种方式) 支持设置图片处理 支持多站点 插件更多详细介绍和安装:https://github.com/sy-records/upyun-uss-wordpress 其他插件 腾讯云COS:GitHub,WordPress Plugins 华为云OBS:GitHub,WordPress Plugins 七牛云KODO:GitHub,WordPress Plugins 阿里云OSS:GitHub,WordPress Plugins 作者博客 沈唁志 QQ交流群:887595381
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C