cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forupcasted-s3-offload upcasted-s3-offload

Direction: descending
Jun 16, 2026

Upcasted S3 Offload – AWS S3, Digital Ocean Spaces, Backblaze, Minio and more # 30be2235708b1e3699af48260235ba12008c971e

Date
Feb 28, 2022
Research Description
Upcasted S3 Offload &#8211; AWS S3, DigitalOcean Spaces, Backblaze, MinIO Storage Integration [upcasted-s3-offload] < 3.0.1 WordPress AWS S3 for WordPress Plugin – Upcasted plugin <= 3.0.0 - Sensitive Information Disclosure vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress AWS S3 for WordPress Plugin – Upcasted plugin (versions <= 3.0.0).
Affected versions
max 3.0.1.
Status
vulnerable
Jun 14, 2026

Upcasted S3 Offload &#8211; AWS S3, Digital Ocean Spaces, Backblaze, Minio and more # CVE-2023-33999

CVE, Research URL

CVE-2023-33999

Date
Jun 11, 2026
Research Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This issue affects WP Mail Log: from n/a through 1.0.2.
Affected versions
max 3.0.3.
Status
vulnerable
Feb 16, 2025

Upcasted S3 Offload &#8211; AWS S3, Digital Ocean Spaces, Backblaze, Minio and more # CVE-2025-22676

CVE, Research URL

CVE-2025-22676

Date
Feb 17, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in upcasted AWS S3 for WordPress Plugin – Upcasted upcasted-s3-offload allows Stored XSS.This issue affects AWS S3 for WordPress Plugin – Upcasted: from n/a through <= 3.0.3.
Affected versions
max 3.0.4.
Status
vulnerable
Jun 06, 2024

Upcasted S3 Offload &#8211; AWS S3, Digital Ocean Spaces, Backblaze, Minio and more # e0a41fd30c1d6f11ff8044cd3eda45c9415fc691

Date
Feb 28, 2022
Research Description
Upcasted S3 Offload &#8211; AWS S3, DigitalOcean Spaces, Backblaze, MinIO Storage Integration [upcasted-s3-offload] < 3.0.1 WordPress AWS S3 for WordPress Plugin – Upcasted plugin <= 3.0.0 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress AWS S3 for WordPress Plugin – Upcasted plugin (versions <= 3.0.0).
Affected versions
max 3.0.1.
Status
vulnerable