PluginProbe
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization / trunk
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization vtrunk
4.2.15 4.2.14 4.2.13 4.2.12 4.2.11 4.2.10 4.2.9 4.2.8 4.2.7 4.2.6 4.2.5 2.5.5 2.5.6 2.5.7 3.0.0 3.0.1 3.1.0 3.1.1 3.1.2 3.1.3 3.10.0 3.11.0 3.11.1 3.11.2 3.11.3 All 136 releases
← All changes | inc/media_rename/attachment_edit.php +25 -1 4.2.5 → trunk View file →
@@ -91,8 +91,9 @@
91 91 'ajaxURL' => admin_url( 'admin-ajax.php' ),
92 92 'maxFileSize' => $max_file_size,
93 93 'attachmentId' => $id,
94 94 'mimeType' => $mime_type,
95 + 'nonce' => wp_create_nonce( 'optml_replace_media_nonce' ),
95 96 'i18n' => [
96 97 'maxFileSizeError' => $max_file_size_error,
97 98 'replaceFileError' => __( 'Error replacing file', 'optimole-wp' ),
98 99 ],
@@ -328,10 +329,22 @@
328 329 /**
329 330 * Replace the file
330 331 */
331 332 public function replace_file() {
332 - $id = (int) sanitize_text_field( $_POST['attachment_id'] );
333 + if ( ! check_ajax_referer( 'optml_replace_media_nonce', 'optml_replace_nonce', false ) ) {
334 + wp_send_json_error( __( 'Security check failed', 'optimole-wp' ) );
335 + }
333 336
337 + $id = absint( $_POST['attachment_id'] ?? 0 );
338 +
339 + if ( ! $id ) {
340 + wp_send_json_error( __( 'Invalid attachment ID', 'optimole-wp' ) );
341 + }
342 +
343 + if ( get_post_type( $id ) !== 'attachment' ) {
344 + wp_send_json_error( __( 'Invalid attachment ID', 'optimole-wp' ) );
345 + }
346 +
334 347 if ( ! current_user_can( 'edit_post', $id ) ) {
335 348 wp_send_json_error( __( 'You are not allowed to replace this file', 'optimole-wp' ) );
336 349 }
337 350
@@ -336,8 +349,19 @@
336 349 }
337 350
338 351 if ( ! isset( $_FILES['file'] ) ) {
339 352 wp_send_json_error( __( 'No file uploaded', 'optimole-wp' ) );
353 + }
354 +
355 + $file_info = wp_check_filetype_and_ext( $_FILES['file']['tmp_name'], $_FILES['file']['name'] );
356 +
357 + if ( empty( $file_info['type'] ) ) {
358 + wp_send_json_error( __( 'Could not determine uploaded file type', 'optimole-wp' ) );
359 + }
360 +
361 + $original_mime = get_post_mime_type( $id );
362 + if ( $file_info['type'] !== $original_mime ) {
363 + wp_send_json_error( __( 'The uploaded file type does not match the original file type.', 'optimole-wp' ) );
340 364 }
341 365
342 366 $replacer = new Optml_Attachment_Replace( $id, $_FILES['file'] );
343 367