PluginProbe
Extendify / 3.2.1
Extendify v3.2.1
3.2.1 3.2.0 3.1.6 3.1.5 3.1.4 3.1.3 3.1.2 3.1.1 3.1.0 3.0.6 3.0.5 3.0.4 trunk 0.1.0 0.10.0 0.10.1 0.10.2 0.11.0 0.11.1 0.2.0 0.3.0 0.3.1 0.4.0 0.5.0 0.6.0 All 127 releases
← All changes | app/Shared/Services/Import/ImageUploader.php +22 -3 3.1.23.2.1 View file →
@@ -40,8 +40,27 @@
40 40 'extendify.com',
41 41 ];
42 42
43 43 /**
44 + * Check whether the url points at one of our image domains.
45 + *
46 + * @param string $url The image url to check.
47 + * @return bool
48 + */
49 + public static function isAllowedImageHost($url)
50 + {
51 + $host = strtolower((string) wp_parse_url($url, PHP_URL_HOST));
52 +
53 + foreach (self::$imagesDomains as $domain) {
54 + if ($host === $domain || str_ends_with($host, '.' . $domain)) {
55 + return true;
56 + }
57 + }
58 +
59 + return false;
60 + }
61 +
62 + /**
44 63 * Upload the image and return the attachment information
45 64 * If the attachment is already there, then return the
46 65 * attachment information only.
47 66 *
@@ -77,13 +96,13 @@
77 96 if (!array_key_exists($fileMimeType, $this->mimes)) {
78 97 return new \WP_Error(2002, 'File type is not allowed.');
79 98 }
80 99
81 - if (!preg_match('(' . implode('|', array_map('preg_quote', self::$imagesDomains)) . ')i', $image)) {
100 + if (!self::isAllowedImageHost($image)) {
82 101 $imageUrl = esc_url_raw($image);
83 102 } else {
84 103 $parsedUrl = wp_parse_url($image);
85 - parse_str($parsedUrl['query'], $params);
104 + parse_str(($parsedUrl['query'] ?? ''), $params);
86 105
87 106 if (!isset($params['w'])) {
88 107 $params['w'] = 1280;
89 108 }
@@ -208,9 +227,9 @@
208 227 * }
209 228 */
210 229 protected function upload($imageUrl, $imageSha, $fileMimeType)
211 230 {
212 - $response = wp_remote_get($imageUrl);
231 + $response = wp_safe_remote_get($imageUrl);
213 232 $body = trim(wp_remote_retrieve_body($response));
214 233 return wp_upload_bits($imageSha . $this->mimes[$fileMimeType], null, $body);
215 234 }
216 235