| @@ -91,8 +91,9 @@ | ||
| 91 | 91 | 'ajaxURL' => admin_url( 'admin-ajax.php' ), |
| 92 | 92 | 'maxFileSize' => $max_file_size, |
| 93 | 93 | 'attachmentId' => $id, |
| 94 | 94 | 'mimeType' => $mime_type, |
| 95 | + 'nonce' => wp_create_nonce( 'optml_replace_media_nonce' ), | |
| 95 | 96 | 'i18n' => [ |
| 96 | 97 | 'maxFileSizeError' => $max_file_size_error, |
| 97 | 98 | 'replaceFileError' => __( 'Error replacing file', 'optimole-wp' ), |
| 98 | 99 | ], |
| @@ -328,10 +329,22 @@ | ||
| 328 | 329 | /** |
| 329 | 330 | * Replace the file |
| 330 | 331 | */ |
| 331 | 332 | public function replace_file() { |
| 332 | - $id = (int) sanitize_text_field( $_POST['attachment_id'] ); | |
| 333 | + if ( ! check_ajax_referer( 'optml_replace_media_nonce', 'optml_replace_nonce', false ) ) { | |
| 334 | + wp_send_json_error( __( 'Security check failed', 'optimole-wp' ) ); | |
| 335 | + } | |
| 333 | 336 | |
| 337 | + $id = absint( $_POST['attachment_id'] ?? 0 ); | |
| 338 | + | |
| 339 | + if ( ! $id ) { | |
| 340 | + wp_send_json_error( __( 'Invalid attachment ID', 'optimole-wp' ) ); | |
| 341 | + } | |
| 342 | + | |
| 343 | + if ( get_post_type( $id ) !== 'attachment' ) { | |
| 344 | + wp_send_json_error( __( 'Invalid attachment ID', 'optimole-wp' ) ); | |
| 345 | + } | |
| 346 | + | |
| 334 | 347 | if ( ! current_user_can( 'edit_post', $id ) ) { |
| 335 | 348 | wp_send_json_error( __( 'You are not allowed to replace this file', 'optimole-wp' ) ); |
| 336 | 349 | } |
| 337 | 350 | |
| @@ -336,8 +349,19 @@ | ||
| 336 | 349 | } |
| 337 | 350 | |
| 338 | 351 | if ( ! isset( $_FILES['file'] ) ) { |
| 339 | 352 | wp_send_json_error( __( 'No file uploaded', 'optimole-wp' ) ); |
| 353 | + } | |
| 354 | + | |
| 355 | + $file_info = wp_check_filetype_and_ext( $_FILES['file']['tmp_name'], $_FILES['file']['name'] ); | |
| 356 | + | |
| 357 | + if ( empty( $file_info['type'] ) ) { | |
| 358 | + wp_send_json_error( __( 'Could not determine uploaded file type', 'optimole-wp' ) ); | |
| 359 | + } | |
| 360 | + | |
| 361 | + $original_mime = get_post_mime_type( $id ); | |
| 362 | + if ( $file_info['type'] !== $original_mime ) { | |
| 363 | + wp_send_json_error( __( 'The uploaded file type does not match the original file type.', 'optimole-wp' ) ); | |
| 340 | 364 | } |
| 341 | 365 | |
| 342 | 366 | $replacer = new Optml_Attachment_Replace( $id, $_FILES['file'] ); |
| 343 | 367 | |