PluginProbe
Yatra – Travel Booking & Tour Operator Software / 3.0.16
Yatra – Travel Booking & Tour Operator Software v3.0.16
3.0.16 3.0.15 3.0.14 3.0.14.1 3.0.14.2 3.0.12 3.0.13 3.0.11 3.0.10 3.0.9 3.0.8 3.0.7 3.0.6 3.0.5 3.0.5.1 3.0.4 3.0.3 3.0.2.9 3.0.2.7 3.0.2.8 3.0.2.6 trunk 1.0.0 2.0.0 2.0.1 All 84 releases
← All changes | app/Controllers/ItemController.php +14 -1 3.0.2.7 → 3.0.16 View file →
@@ -94,9 +94,13 @@
94 94 case 'PATCH':
95 95 case 'DELETE':
96 96 return current_user_can('yatra_edit_trips');
97 97 default:
98 - return current_user_can('manage_options');
98 + // Unknown HTTP method — deny explicitly. The earlier
99 + // fallback to `manage_options` was a regression that
100 + // silently broadened admin-only access for any verb not
101 + // in the explicit switch.
102 + return false;
99 103 }
100 104 }
101 105
102 106 public function get_items(WP_REST_Request $request)
@@ -244,8 +248,17 @@
244 248 if (!empty($type->icon)) {
245 249 $icon_data = maybe_unserialize($type->icon);
246 250 if (is_array($icon_data) && isset($icon_data['value'])) {
247 251 $prepared['type_icon'] = $icon_data['value'];
252 + if (
253 + isset($icon_data['type'], $icon_data['provider'])
254 + && $icon_data['type'] === 'icon'
255 + ) {
256 + $p = sanitize_key((string) $icon_data['provider']);
257 + if (in_array($p, ['fa-solid', 'fa-regular'], true)) {
258 + $prepared['type_icon_provider'] = $p;
259 + }
260 + }
248 261 } elseif (is_string($type->icon)) {
249 262 $prepared['type_icon'] = $type->icon;
250 263 }
251 264 }