PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | modules/infinite-scroll/infinity.php +32 -2 16.3-a.7 → 16.3 View file →
@@ -1657,15 +1657,45 @@
1657 1657 );
1658 1658
1659 1659 if ( isset( $_REQUEST['query_args'] ) && is_array( $_REQUEST['query_args'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- no site changes.
1660 1660 foreach ( wp_unslash( $_REQUEST['query_args'] ) as $var => $value ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized -- no site changes, sanitized below.
1661 - if ( in_array( $var, $allowed_vars, true ) && ! empty( $value ) ) {
1662 - $query_args[ $var ] = filter_var( $value );
1661 + if ( ! in_array( $var, $allowed_vars, true ) || empty( $value ) ) {
1662 + continue;
1663 1663 }
1664 +
1665 + if ( 'post_type' === $var && ! self::is_queryable_post_type( $value ) ) {
1666 + continue;
1667 + }
1668 +
1669 + $query_args[ $var ] = filter_var( $value );
1664 1670 }
1665 1671 }
1666 1672
1667 1673 return $query_args;
1674 + }
1675 +
1676 + /**
1677 + * Whether a post type supplied with the request may be queried on the front end.
1678 + *
1679 + * Core applies this test to the main query in WP::parse_request(), but the
1680 + * Infinite Scroll query is a secondary one and never passes through it.
1681 + *
1682 + * @param mixed $post_type Post type name, or array of names, from the request.
1683 + * @return bool
1684 + */
1685 + private static function is_queryable_post_type( $post_type ) {
1686 + // WP_Query expands 'any' to the types that opted into search results.
1687 + if ( 'any' === $post_type ) {
1688 + return true;
1689 + }
1690 +
1691 + foreach ( (array) $post_type as $type ) {
1692 + if ( ! is_string( $type ) || ! is_post_type_viewable( $type ) ) {
1693 + return false;
1694 + }
1695 + }
1696 +
1697 + return true;
1668 1698 }
1669 1699
1670 1700 /**
1671 1701 * Rendering fallback used when themes don't specify their own handler.