PluginProbe ʕ •ᴥ•ʔ
Advanced Access Manager – Access Governance for WordPress / trunk
Advanced Access Manager – Access Governance for WordPress vtrunk
6.8.4 6.8.5 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13 6.9.14 6.9.15 6.9.16 6.9.17 6.9.18 6.9.19 6.9.2 6.9.20 6.9.21 6.9.22 6.9.23 6.9.24 6.9.25 6.9.26 6.9.27 6.9.28 6.9.29 6.9.3 6.9.30 6.9.31 6.9.32 6.9.33 6.9.34 6.9.35 6.9.36 6.9.37 6.9.38 6.9.39 6.9.4 6.9.41 6.9.42 6.9.43 6.9.44 6.9.45 6.9.46 6.9.47 6.9.48 6.9.49 6.9.5 6.9.51 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.0-alpha.6 7.0.0-alpha.7 7.0.0-beta.1 7.0.0-rc1 7.0.0-rc2 7.0.0-rc3 7.0.1 7.0.10 7.0.11 7.0.2 7.0.3 7.0.4 7.0.5 7.0.6 7.0.7 7.0.8 7.0.9 7.1.0 7.1.1 trunk 3.0 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.6.1 4.6.2 4.7 4.7.1 4.7.2 4.7.5 4.7.6 4.8 4.8.1 4.9 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 4.9.5.1 4.9.5.2 5.0 5.0.1 5.0.2 5.0.3 5.0.4 5.0.5 5.0.6 5.0.7 5.0.8 5.1 5.1.1 5.10 5.11 5.2 5.2.1 5.2.5 5.2.6 5.2.7 5.3 5.3.1 5.3.2 5.3.3 5.3.4 5.3.5 5.4 5.4.1 5.4.2 5.4.3 5.4.3.1 5.4.3.2 5.5 5.5.1 5.5.2 5.6 5.6.1 5.6.1.1 5.7 5.7.1 5.7.2 5.7.3 5.8 5.8.1 5.8.2 5.8.3 5.9 5.9.1 5.9.1.1 5.9.2 5.9.2.1 5.9.3 5.9.4 5.9.5 5.9.6 5.9.6.1 5.9.6.2 5.9.6.3 5.9.7 5.9.7.1 5.9.7.2 5.9.7.3 5.9.8 5.9.8.1 5.9.9 5.9.9.1 6.0.0 6.0.1 6.0.2 6.0.3 6.0.4 6.0.5 6.1.0 6.1.1 6.2.0 6.2.1 6.2.2 6.3.0 6.3.1 6.3.2 6.3.3 6.4.0 6.4.1 6.4.2 6.4.3 6.5.0 6.5.1 6.5.2 6.5.3 6.5.4 6.6.0 6.6.1 6.6.2 6.6.3 6.6.4 6.7.0 6.7.1 6.7.2 6.7.3 6.7.4 6.7.5 6.7.6 6.7.7 6.7.8 6.7.9 6.8.0 6.8.1 6.8.2 6.8.3
advanced-access-manager / application / Audit / HighPrivilegeRoleCheck.php
advanced-access-manager / application / Audit Last commit date
AuditCheckTrait.php 1 year ago CoreUserRoleOptionIntegrityCheck.php 1 year ago EditableFileSystemCheck.php 7 months ago ElevatedCoreRoleCheck.php 7 months ago EmptyUnusedRoleCheck.php 7 months ago HighPrivilegeContentModeratorCheck.php 7 months ago HighPrivilegeOrElevatedUserCheck.php 7 months ago HighPrivilegeRoleCheck.php 7 months ago HighPrivilegeUserCountCheck.php 7 months ago RestfulAutoDiscoverEndpointCheck.php 7 months ago RoleCapabilityNamingConventionCheck.php 7 months ago RoleIntegrityCheck.php 7 months ago RoleTransparencyCheck.php 7 months ago XmlRpcEndpointCheck.php 7 months ago
HighPrivilegeRoleCheck.php
167 lines
1 <?php
2
3 /**
4 * ======================================================================
5 * LICENSE: This file is subject to the terms and conditions defined in *
6 * file 'license.txt', which is part of this source code package. *
7 * ======================================================================
8 */
9
10 /**
11 * Check for the high privilege roles
12 *
13 * @package AAM
14 * @version 7.0.0
15 */
16 class AAM_Audit_HighPrivilegeRoleCheck
17 {
18
19 use AAM_Audit_AuditCheckTrait;
20
21 /**
22 * Step ID
23 *
24 * @version 7.0.0
25 */
26 const ID = 'high_privilege_roles';
27
28 /**
29 * List of roles that are allowed to be high-privileged
30 *
31 * @version 7.0.0
32 */
33 const WHITELISTED_ROLES = [
34 'administrator'
35 ];
36
37 /**
38 * List of core capabilities that can cause significant damage to the site
39 *
40 * @version 7.0.0
41 */
42 const HIGH_PRIVILEGE_CAPS = [
43 'edit_themes',
44 'edit_plugins',
45 'edit_files',
46 'activate_plugins',
47 'manage_options',
48 'delete_users',
49 'create_users',
50 'unfiltered_upload',
51 'unfiltered_html',
52 'update_plugins',
53 'delete_plugins',
54 'install_plugins',
55 'update_themes',
56 'install_themes',
57 'update_core',
58 'promote_users',
59 'delete_themes'
60 ];
61
62 /**
63 * Run the check
64 *
65 * @return array
66 *
67 * @access public
68 * @static
69 *
70 * @version 7.0.0
71 */
72 public static function run()
73 {
74 $issues = [];
75 $response = [ 'is_completed' => true ];
76
77 try {
78 // Scan for high privilege roles
79 array_push(
80 $issues,
81 ...self::_scan_for_high_privilege_roles(self::_read_role_key_option())
82 );
83 } catch (Exception $e) {
84 array_push($issues, self::_format_issue(
85 'APPLICATION_ERROR',
86 [
87 'message' => $e->getMessage()
88 ],
89 'error'
90 ));
91 }
92
93 if (count($issues) > 0) {
94 $response['issues'] = $issues;
95 }
96
97 // Determine final status for the check
98 self::_determine_check_status($response);
99
100 return $response;
101 }
102
103 /**
104 * Get a collection of error messages for current step
105 *
106 * @return array
107 * @access private
108 * @static
109 *
110 * @version 7.0.0
111 */
112 private static function _get_message_templates()
113 {
114 return [
115 'HIGH_PRIVILEGE_CAPS_ROLE' => __(
116 'Detected high-privilege role %s (%s) with caps: %s',
117 'advanced-access-manager'
118 )
119 ];
120 }
121
122 /**
123 * Scan for high-privilege roles that are not whitelisted
124 *
125 * @param array $db_roles
126 *
127 * @return array
128 *
129 * @access private
130 * @static
131 *
132 * @version 7.0.0
133 */
134 private static function _scan_for_high_privilege_roles($db_roles)
135 {
136 $response = [];
137
138 foreach($db_roles as $role_id => $role) {
139 if (!in_array($role_id, self::WHITELISTED_ROLES)) {
140 $assigned_caps = array_keys(
141 array_filter($role['capabilities'], function($v) {
142 return !empty($v);
143 })
144 );
145
146 $matched = array_intersect($assigned_caps, self::HIGH_PRIVILEGE_CAPS);
147
148 if (!empty($matched)) {
149 array_push($response, self::_format_issue(
150 'HIGH_PRIVILEGE_CAPS_ROLE',
151 [
152 'name' => translate_user_role(
153 !empty($role['name']) ? $role['name'] : $role_id
154 ),
155 'slug' => $role_id,
156 'caps' => $matched
157 ],
158 'critical'
159 ));
160 }
161 }
162 }
163
164 return $response;
165 }
166
167 }