PluginProbe
GiveWP – Donation Plugin and Fundraising Platform / 4.18.0
GiveWP – Donation Plugin and Fundraising Platform v4.18.0
4.18.0 4.17.0 4.16.9 4.16.8.1 4.16.8 4.16.7.2 4.16.7.1 4.16.7 4.16.6.1 4.16.6 4.16.5.1 4.16.5 4.16.4 4.16.3 4.16.2 4.16.1 4.16.0 4.15.5 4.15.4 4.15.3 4.15.2 4.15.1 4.15.0 2.3.0 2.3.1 All 257 releases
← All changes | includes/class-give-email-access.php +20 -2 4.16.5 → 4.18.0 View file →
@@ -213,8 +213,9 @@
213 213
214 214 /**
215 215 * This function is used to fetch the token value from query string or cookies based on availability.
216 216 *
217 + * @since 4.16.7 Return an empty string for non-string token values.
217 218 * @since 2.4.1
218 219 * @access public
219 220 *
220 221 * @return string
@@ -227,9 +228,9 @@
227 228 if ( empty( $token ) ) {
228 229 $token = isset( $_COOKIE['give_nl'] ) ? give_clean( $_COOKIE['give_nl'] ) : '';
229 230 }
230 231
231 - return $token;
232 + return is_string( $token ) ? $token : '';
232 233 }
233 234
234 235 /**
235 236 * Has the user authenticated?
@@ -269,8 +270,9 @@
269 270
270 271 /**
271 272 * Is this a valid token?
272 273 *
274 + * @since 4.16.7 Only accept non-empty string tokens.
273 275 * @since 1.0
274 276 * @access public
275 277 *
276 278 * @param $token string The token.
@@ -280,8 +282,13 @@
280 282 public function is_valid_token( $token ) {
281 283
282 284 global $wpdb;
283 285
286 + // A crafted give_nl[]= parameter arrives as an array; reject non-string and empty tokens.
287 + if ( ! is_string( $token ) || '' === $token ) {
288 + return false;
289 + }
290 +
284 291 // Make sure token isn't expired.
285 292 $expires = date( 'Y-m-d H:i:s', time() - $this->token_expiration );
286 293
287 294 $email = $wpdb->get_var(
@@ -343,8 +350,10 @@
343 350
344 351 /**
345 352 * Is this a valid verify key?
346 353 *
354 + * @since 4.18.0 Verify keys expire with the same window as access tokens.
355 + * @since 4.16.7 Only accept non-empty string tokens.
347 356 * @since 1.0
348 357 * @access public
349 358 *
350 359 * @param $token string The token.
@@ -354,11 +363,20 @@
354 363 public function is_valid_verify_key( $token ) {
355 364 /* @var WPDB $wpdb */
356 365 global $wpdb;
357 366
367 + // A crafted give_nl[]= parameter arrives as an array; reject non-string and empty tokens.
368 + if ( ! is_string( $token ) || '' === $token ) {
369 + return false;
370 + }
371 +
372 + // A verify key expires with the same window as an access token, so a
373 + // key generated before that window can no longer be redeemed.
374 + $expires = date( 'Y-m-d H:i:s', time() - $this->token_expiration );
375 +
358 376 // See if the verify_key exists.
359 377 $row = $wpdb->get_row(
360 - $wpdb->prepare( "SELECT id, email FROM {$wpdb->donors} WHERE verify_key = %s LIMIT 1", $token )
378 + $wpdb->prepare( "SELECT id, email FROM {$wpdb->donors} WHERE verify_key = %s AND verify_throttle >= %s LIMIT 1", $token, $expires )
361 379 );
362 380
363 381 $now = date( 'Y-m-d H:i:s' );
364 382