PluginProbe
Extendify / trunk
Extendify vtrunk
3.2.1 3.2.0 3.1.6 3.1.5 3.1.4 3.1.3 3.1.2 3.1.1 3.1.0 3.0.6 3.0.5 3.0.4 trunk 0.1.0 0.10.0 0.10.1 0.10.2 0.11.0 0.11.1 0.2.0 0.3.0 0.3.1 0.4.0 0.5.0 0.6.0 All 127 releases
← All changes | app/Shared/Services/Import/BlocksUpdater.php +2 -6 3.1.4 → trunk View file →
@@ -140,14 +140,10 @@
140 140 $html = new \WP_HTML_Tag_Processor($htmlContent);
141 141 $html->next_tag('img');
142 142 $src = $html->get_attribute('src');
143 143
144 - return $src && preg_match(
145 - '(' . implode('|', array_map('preg_quote', ImageUploader::$imagesDomains, ['/'])) . ')i',
146 - $src
147 - )
148 - ? $src
149 - : '';
144 + // Feeds a server-side fetch, so a path-matched domain would let any host through.
145 + return ($src && ImageUploader::isAllowedImageHost($src)) ? $src : '';
150 146 }
151 147
152 148 /**
153 149 * Update the content of the block to remove the targeted class attribute.