PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.1
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.1
16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 All 504 releases
← All changes | modules/shortcodes/gist.php +16 -5 13.5.216.3-a.1 View file →
@@ -17,8 +17,12 @@
17 17 *
18 18 * @package automattic/jetpack
19 19 */
20 20
21 +if ( ! defined( 'ABSPATH' ) ) {
22 + exit( 0 );
23 +}
24 +
21 25 wp_embed_register_handler( 'github-gist', '#https?://gist\.github\.com/([a-zA-Z0-9/]+)(\#file\-[a-zA-Z0-9\_\-]+)?#', 'github_gist_embed_handler' );
22 26 add_shortcode( 'gist', 'github_gist_shortcode' );
23 27
24 28 /**
@@ -83,14 +87,21 @@
83 87 if ( ! empty( $parsed_url['fragment'] ) ) {
84 88 $gist_info['file'] = preg_replace( '/(?:file-)(.+)/', '$1', $parsed_url['fragment'] );
85 89 }
86 90
87 - // Keep the unique identifier without any leading or trailing slashes.
88 - if ( ! empty( $parsed_url['path'] ) ) {
89 - $gist_info['id'] = trim( $parsed_url['path'], '/' );
90 - // Overwrite $gist with our identifier to clean it up below.
91 - $gist = $gist_info['id'];
91 + // Validate the path structure - should be either username/gistid or just gistid
92 + $path = trim( $parsed_url['path'], '/' );
93 + if ( ! preg_match( '#^([a-zA-Z0-9_-]+/)?([a-f0-9]+)$#', $path ) ) {
94 + return array(
95 + 'id' => '',
96 + 'file' => '',
97 + 'ts' => 8,
98 + );
92 99 }
100 +
101 + $gist_info['id'] = $path;
102 + // Reassign $gist with the identifier to clean it up below.
103 + $gist = $path;
93 104
94 105 // Parse the query args to obtain the tab spacing.
95 106 if ( ! empty( $parsed_url['query'] ) ) {
96 107 $query_args = array();