PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.5
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.5
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
← All changes | json-endpoints/jetpack/class.jetpack-json-api-themes-new-endpoint.php +19 -6 12.3.2 → 16.3-a.5 View file →
@@ -1,17 +1,24 @@
1 1 <?php // phpcs:ignore WordPress.Files.FileName.InvalidClassFileName
2 2
3 +use Automattic\Jetpack\Automatic_Install_Skin;
4 +
5 +if ( ! defined( 'ABSPATH' ) ) {
6 + exit( 0 );
7 +}
8 +
3 9 require_once ABSPATH . 'wp-admin/includes/class-wp-upgrader.php';
4 10 require_once ABSPATH . 'wp-admin/includes/file.php';
5 11
6 -use Automattic\Jetpack\Automatic_Install_Skin;
7 -
8 12 /**
9 13 * Themes new endpoint class.
10 14 *
11 15 * /sites/%s/themes/%s/install
16 + *
17 + * @phan-constructor-used-for-side-effects
12 18 */
13 19 class Jetpack_JSON_API_Themes_New_Endpoint extends Jetpack_JSON_API_Themes_Endpoint {
20 + use Jetpack_JSON_API_Attachment_Ownership_Trait;
14 21
15 22 /**
16 23 * Needed capabilities.
17 24 *
@@ -45,11 +52,17 @@
45 52 protected function validate_call( $_blog_id, $capability, $check_manage_active = true ) {
46 53 $validate = parent::validate_call( $_blog_id, $capability, $check_manage_active );
47 54 if ( is_wp_error( $validate ) ) {
48 55 // Lets delete the attachment... if the user doesn't have the right permissions to do things.
56 + // Only clean up an upload the caller actually owns. This runs *after* the capability check
57 + // has already failed, so without the ownership guard any connected user could name someone
58 + // else's attachment and have it hard-deleted on their behalf.
49 59 $args = $this->input();
50 - if ( isset( $args['zip'][0]['id'] ) ) {
51 - wp_delete_attachment( $args['zip'][0]['id'], true );
60 + if ( isset( $args['zip'][0]['id'] ) && is_scalar( $args['zip'][0]['id'] ) ) {
61 + $attachment_id = (int) $args['zip'][0]['id'];
62 + if ( true === $this->validate_attachment_ownership( $attachment_id ) ) {
63 + wp_delete_attachment( $attachment_id, true );
64 + }
52 65 }
53 66 }
54 67
55 68 return $validate;
@@ -95,10 +108,10 @@
95 108 $after_install_list = wp_get_themes();
96 109 $plugin = array_values( array_diff( array_keys( $after_install_list ), array_keys( $pre_install_list ) ) );
97 110
98 111 if ( ! $result ) {
99 - $error_code = $upgrader->skin->get_main_error_code();
100 - $message = $upgrader->skin->get_main_error_message();
112 + $error_code = $skin->get_main_error_code();
113 + $message = $skin->get_main_error_message();
101 114 if ( empty( $message ) ) {
102 115 $message = __( 'An unknown error occurred during installation', 'jetpack' );
103 116 }
104 117