PluginProbe
Extendify / 3.2.2
Extendify v3.2.2
3.2.2 3.2.1 3.2.0 3.1.6 3.1.5 3.1.4 3.1.3 3.1.2 3.1.1 3.1.0 3.0.6 3.0.5 3.0.4 trunk 0.1.0 0.10.0 0.10.1 0.10.2 0.11.0 0.11.1 0.2.0 0.3.0 0.3.1 0.4.0 0.5.0 All 128 releases
← All changes | app/Shared/Services/Import/BlocksUpdater.php +2 -6 3.1.4 → 3.2.2 View file →
@@ -140,14 +140,10 @@
140 140 $html = new \WP_HTML_Tag_Processor($htmlContent);
141 141 $html->next_tag('img');
142 142 $src = $html->get_attribute('src');
143 143
144 - return $src && preg_match(
145 - '(' . implode('|', array_map('preg_quote', ImageUploader::$imagesDomains, ['/'])) . ')i',
146 - $src
147 - )
148 - ? $src
149 - : '';
144 + // Feeds a server-side fetch, so a path-matched domain would let any host through.
145 + return ($src && ImageUploader::isAllowedImageHost($src)) ? $src : '';
150 146 }
151 147
152 148 /**
153 149 * Update the content of the block to remove the targeted class attribute.