PluginProbe
King Addons for Elementor – 100+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce Builder, Mega Menu, Popup Builder / 51.1.87
King Addons for Elementor – 100+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce Builder, Mega Menu, Popup Builder v51.1.87
51.1.87 51.1.86 51.1.84 51.1.85 51.1.83 51.1.82 51.1.81 51.1.79 51.1.78 51.1.77 51.1.76 51.1.74 51.1.75 51.1.65 51.1.64 51.1.63 trunk 51.1.14 51.1.2 51.1.35 51.1.36 51.1.37 51.1.38 51.1.39 51.1.44 All 41 releases
← All changes | includes/widgets/Login_Register_Form/Security_Manager.php +13 -4 51.1.14 → 51.1.87 View file →
@@ -58,9 +58,9 @@
58 58 $attempts++;
59 59 set_transient($transient_key, $attempts, self::LOCKOUT_DURATION);
60 60
61 61 // Log security event
62 - error_log("King Addons Security: Failed {$action} attempt #{$attempts} from IP {$ip_address}");
62 + // error_log("King Addons Security: Failed {$action} attempt #{$attempts} from IP {$ip_address}");
63 63
64 64 return $attempts;
65 65 }
66 66
@@ -138,10 +138,19 @@
138 138 'error' => esc_html__('File type mismatch detected. Upload rejected for security.', 'king-addons')
139 139 ];
140 140 }
141 141
142 - // Check for malicious content in text files
142 + // Check for malicious content in text files (limit file size to prevent DoS)
143 143 if (in_array($file_type['type'], ['text/plain', 'application/pdf'])) {
144 + // Security fix: Check file size before reading to prevent DoS
145 + $file_size = filesize($file_data['tmp_name']);
146 + if ($file_size > 1024 * 1024) { // 1MB limit for content scanning
147 + return [
148 + 'valid' => false,
149 + 'error' => esc_html__('File too large for content scanning.', 'king-addons')
150 + ];
151 + }
152 +
144 153 $content = file_get_contents($file_data['tmp_name']);
145 154 if (self::contains_malicious_content($content)) {
146 155 return [
147 156 'valid' => false,
@@ -183,9 +192,9 @@
183 192 }
184 193
185 194 // Validate email domain for additional security
186 195 if (!empty($sanitized['email']) && !self::is_safe_email_domain($sanitized['email'])) {
187 - error_log("King Addons Security: Suspicious email domain from {$provider}: {$sanitized['email']}");
196 + // error_log("King Addons Security: Suspicious email domain from {$provider}: {$sanitized['email']}");
188 197 }
189 198
190 199 return $sanitized;
191 200 }
@@ -212,9 +221,9 @@
212 221 ]);
213 222
214 223 foreach ($suspicious_patterns as $pattern) {
215 224 if (preg_match($pattern, $text_to_check)) {
216 - error_log("King Addons Security: Suspicious registration pattern detected: {$pattern}");
225 + // error_log("King Addons Security: Suspicious registration pattern detected: {$pattern}");
217 226 return true;
218 227 }
219 228 }
220 229