| @@ -350,8 +350,9 @@ | ||
| 350 | 350 | |
| 351 | 351 | /** |
| 352 | 352 | * Is this a valid verify key? |
| 353 | 353 | * |
| 354 | + * @since 4.18.0 Verify keys expire with the same window as access tokens. | |
| 354 | 355 | * @since 4.16.7 Only accept non-empty string tokens. |
| 355 | 356 | * @since 1.0 |
| 356 | 357 | * @access public |
| 357 | 358 | * |
| @@ -367,11 +368,15 @@ | ||
| 367 | 368 | if ( ! is_string( $token ) || '' === $token ) { |
| 368 | 369 | return false; |
| 369 | 370 | } |
| 370 | 371 | |
| 372 | + // A verify key expires with the same window as an access token, so a | |
| 373 | + // key generated before that window can no longer be redeemed. | |
| 374 | + $expires = date( 'Y-m-d H:i:s', time() - $this->token_expiration ); | |
| 375 | + | |
| 371 | 376 | // See if the verify_key exists. |
| 372 | 377 | $row = $wpdb->get_row( |
| 373 | - $wpdb->prepare( "SELECT id, email FROM {$wpdb->donors} WHERE verify_key = %s LIMIT 1", $token ) | |
| 378 | + $wpdb->prepare( "SELECT id, email FROM {$wpdb->donors} WHERE verify_key = %s AND verify_throttle >= %s LIMIT 1", $token, $expires ) | |
| 374 | 379 | ); |
| 375 | 380 | |
| 376 | 381 | $now = date( 'Y-m-d H:i:s' ); |
| 377 | 382 | |