Input validation vulnerability in USS Upyun 1.5.0

The USS Upyun plugin used for WordPress has a security issue known as Cross-Site Request Forgery. This affects all versions up to and including 1.5.0. The problem lies in the way the plugin handles certain forms, specifically the uss_set form, which lacks proper validation. This means that someone without proper authorization can change important settings for Upyun cloud storage, such as the bucket name, operator credentials, upload paths, and image processing parameters. They can do this by tricking a site administrator into clicking on a link.

Detected in:

USS Upyun fixed vulnerable versions: >= * <= 1.5.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.