PluginProbe
GiveWP – Donation Plugin and Fundraising Platform / 4.18.0
GiveWP – Donation Plugin and Fundraising Platform v4.18.0
4.18.0 4.17.0 4.16.9 4.16.8.1 4.16.8 4.16.7.2 4.16.7.1 4.16.7 4.16.6.1 4.16.6 4.16.5.1 4.16.5 4.16.4 4.16.3 4.16.2 4.16.1 4.16.0 4.15.5 4.15.4 4.15.3 4.15.2 4.15.1 4.15.0 2.3.0 2.3.1 All 257 releases
← All changes | includes/class-give-email-access.php +6 -1 4.16.8.1 → 4.18.0 View file →
@@ -350,8 +350,9 @@
350 350
351 351 /**
352 352 * Is this a valid verify key?
353 353 *
354 + * @since 4.18.0 Verify keys expire with the same window as access tokens.
354 355 * @since 4.16.7 Only accept non-empty string tokens.
355 356 * @since 1.0
356 357 * @access public
357 358 *
@@ -367,11 +368,15 @@
367 368 if ( ! is_string( $token ) || '' === $token ) {
368 369 return false;
369 370 }
370 371
372 + // A verify key expires with the same window as an access token, so a
373 + // key generated before that window can no longer be redeemed.
374 + $expires = date( 'Y-m-d H:i:s', time() - $this->token_expiration );
375 +
371 376 // See if the verify_key exists.
372 377 $row = $wpdb->get_row(
373 - $wpdb->prepare( "SELECT id, email FROM {$wpdb->donors} WHERE verify_key = %s LIMIT 1", $token )
378 + $wpdb->prepare( "SELECT id, email FROM {$wpdb->donors} WHERE verify_key = %s AND verify_throttle >= %s LIMIT 1", $token, $expires )
374 379 );
375 380
376 381 $now = date( 'Y-m-d H:i:s' );
377 382