PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | jetpack_vendor/automattic/jetpack-waf/src/class-waf-runtime.php +3 -1 16.2 → 16.3 View file →
@@ -313,9 +313,11 @@
313 313 * @param string $reason Block reason.
314 314 * @param int $status_code Http status code.
315 315 */
316 316 public function block( $action, $rule_id, $reason, $status_code = 403 ) {
317 - if ( 'ip block list' === $reason ) {
317 + // The recovery flow needs transients, `wp_salt()` and `$pagenow`, so it cannot run in
318 + // standalone mode, where the WAF executes from `auto_prepend_file` before WordPress.
319 + if ( 'ip block list' === $reason && defined( 'ABSPATH' ) ) {
318 320 $real_ip = $this->request->get_real_user_ip_address();
319 321
320 322 if ( $this->is_ip_allowed_for_recovery( $real_ip ) ) {
321 323 return;