PluginProbe
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization / 4.2.16
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization v4.2.16
4.2.16 4.2.15 4.2.14 4.2.13 4.2.12 4.2.11 4.2.10 4.2.9 4.2.8 4.2.7 4.2.6 4.2.5 2.5.5 2.5.6 2.5.7 3.0.0 3.0.1 3.1.0 3.1.1 3.1.2 3.1.3 3.10.0 3.11.0 3.11.1 3.11.2 All 137 releases
← All changes | inc/admin.php +52 -10 4.2.15 → 4.2.16 View file →
@@ -109,8 +109,9 @@
109 109 'allow_svg',
110 110 ]
111 111 ); // phpcs:ignore WordPressVIPMinimum.Hooks.RestrictedHooks.upload_mimes
112 112 add_filter( 'wp_handle_upload_prefilter', [ $this, 'check_svg_and_sanitize' ] );
113 + add_filter( 'wp_handle_sideload_prefilter', [ $this, 'sanitize_sideloaded_svg' ] );
113 114 }
114 115
115 116 add_filter( 'themeisle-sdk/survey/' . OPTML_PRODUCT_SLUG, [ $this, 'get_survey_metadata' ], 10, 2 );
116 117 add_action( 'admin_init', [ $this, 'mark_user_with_offload' ] );
@@ -191,26 +192,67 @@
191 192 *
192 193 * @return mixed
193 194 */
194 195 public function check_svg_and_sanitize( $file ) {
196 + if ( ! is_array( $file ) || ! $this->is_svg_file( $file ) ) {
197 + return $file;
198 + }
199 +
200 + if ( ! current_user_can( 'upload_files' ) ) {
201 + $file['error'] = 'Invalid';
202 + return $file;
203 + }
204 +
205 + return $this->sanitize_svg_file( $file );
206 + }
207 +
208 + /**
209 + * Sanitize an SVG stored through wp_handle_sideload().
210 + *
211 + * Sideload callers authorize themselves (the REST media endpoint checks upload_files) and
212 + * background restores run without a user, so only sanitization is applied here.
213 + *
214 + * @param array<string, mixed> $file An array of data for a single file.
215 + *
216 + * @return array<string, mixed>
217 + */
218 + public function sanitize_sideloaded_svg( array $file ): array {
219 + if ( ! $this->is_svg_file( $file ) ) {
220 + return $file;
221 + }
222 +
223 + return $this->sanitize_svg_file( $file );
224 + }
225 +
226 + /**
227 + * Check whether an upload/sideload file array is an SVG.
228 + *
229 + * @param array<string, mixed> $file An array of data for a single file.
230 + *
231 + * @return bool
232 + */
233 + private function is_svg_file( array $file ): bool {
195 234 // Ensure we have a proper file path before processing.
196 235 if ( ! isset( $file['tmp_name'] ) ) {
197 - return $file;
236 + return false;
198 237 }
199 238
200 239 $file_name = isset( $file['name'] ) ? $file['name'] : '';
201 240 $wp_filetype = wp_check_filetype_and_ext( $file['tmp_name'], $file_name );
202 - $type = ! empty( $wp_filetype['type'] ) ? $wp_filetype['type'] : '';
203 241
204 - if ( 'image/svg+xml' === $type ) {
205 - if ( ! current_user_can( 'upload_files' ) ) {
206 - $file['error'] = 'Invalid';
207 - return $file;
208 - }
242 + return ! empty( $wp_filetype['type'] ) && 'image/svg+xml' === $wp_filetype['type'];
243 + }
209 244
210 - if ( ! $this->sanitize_svg( $file['tmp_name'] ) ) {
211 - $file['error'] = 'Invalid';
212 - }
245 + /**
246 + * Sanitize the SVG temp file in place, flagging the upload when it cannot be sanitized.
247 + *
248 + * @param array<string, mixed> $file An array of data for a single file.
249 + *
250 + * @return array<string, mixed>
251 + */
252 + private function sanitize_svg_file( array $file ): array {
253 + if ( ! $this->sanitize_svg( $file['tmp_name'] ) ) {
254 + $file['error'] = 'Invalid';
213 255 }
214 256
215 257 return $file;
216 258 }