PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.7
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.7
16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 All 506 releases
← All changes | _inc/lib/core-api/wpcom-endpoints/class-wpcom-rest-api-v2-endpoint-external-media.php +21 -1 16.2-beta → 16.3-a.7 View file →
@@ -274,8 +274,21 @@
274 274 array( 'status' => 400 )
275 275 );
276 276 }
277 277
278 + // Attaching media to a post requires the ability to edit that post, mirroring
279 + // WP_REST_Attachments_Controller::create_item_permissions_check(). Without this
280 + // check any user with upload_files could parent an attachment to a post they
281 + // cannot edit.
282 + $post_id = (int) $request->get_param( 'post_id' );
283 + if ( $post_id > 0 && ! current_user_can( 'edit_post', $post_id ) ) {
284 + return new WP_Error(
285 + 'rest_cannot_edit',
286 + __( 'Sorry, you are not allowed to upload media to this post.', 'jetpack' ),
287 + array( 'status' => rest_authorization_required_code() )
288 + );
289 + }
290 +
278 291 return true;
279 292 }
280 293
281 294 /**
@@ -399,11 +412,18 @@
399 412 require_once ABSPATH . 'wp-admin/includes/file.php';
400 413 require_once ABSPATH . 'wp-admin/includes/media.php';
401 414 require_once ABSPATH . 'wp-admin/includes/image.php';
402 415
403 - $post_id = $request->get_param( 'post_id' );
416 + $post_id = (int) $request->get_param( 'post_id' );
404 417 $should_proxy = $request->get_param( 'should_proxy' );
405 418 $service = rawurlencode( $request->get_param( 'service' ) );
419 +
420 + // Fail closed: never parent an attachment to a post the caller cannot edit,
421 + // even if a future change lets an unauthorized request reach this handler.
422 + // The permission callback already rejects such requests with a 403.
423 + if ( $post_id > 0 && ! current_user_can( 'edit_post', $post_id ) ) {
424 + $post_id = 0;
425 + }
406 426
407 427 $responses = array();
408 428
409 429 foreach ( $request->get_param( 'media' ) as $item ) {