From 24a235ff91ca06134996b071b46fd2c26cd916de Mon Sep 17 00:00:00 2001 From: Scott Kingsley Clark Date: Wed, 24 Apr 2024 13:37:15 -0500 Subject: [PATCH] Security patch --- classes/Pods.php | 9 +++++++++ includes/data.php | 20 ++++++++++++++++++++ init.php | 4 ++-- package.json | 2 +- readme.txt | 8 +++++++- src/Pods/Blocks/API.php | 5 +++++ ui/front/form.php | 2 +- 7 files changed, 45 insertions(+), 5 deletions(-) diff --git a/classes/Pods.php b/classes/Pods.php index b4f967f7a8..fa1a8bec23 100644 --- a/classes/Pods.php +++ b/classes/Pods.php @@ -4052,6 +4052,15 @@ public function form( $params = null, $label = null, $thank_you = null ) { $fields_only = $params['fields_only']; $output_type = $params['output_type']; + // Sanitize thank_you for security. + if ( ! empty( $thank_you ) ) { + // Additional sanitization. + $thank_you = sanitize_text_field( $thank_you ); + + // Fallback to '' so that the logic below can kick in if the thank you URL was not safe. + $thank_you = pods_enforce_safe_url( $thank_you, '' ); + } + if ( empty( $output_type ) ) { $output_type = 'div'; } diff --git a/includes/data.php b/includes/data.php index cc828a2fa1..ae198e2fb0 100644 --- a/includes/data.php +++ b/includes/data.php @@ -2998,3 +2998,23 @@ function pods_objects_keyed_by_name( $objects ) { return $new_list; } + +/** + * Enforce a URL as safe and fallback to another URL if it is not safe. + * + * @since 3.2.1.1 + * + * @param string $url The URL to enforce as safe. + * @param string|null $fallback_url The fallback URL to use if the URL is not valid. + * + * @return string The safe URL or the fallback URL if that was not valid. + */ +function pods_enforce_safe_url( string $url, ?string $fallback_url = null ) { + $url = wp_sanitize_redirect( $url ); + + if ( null === $fallback_url ) { + $fallback_url = pods_current_url(); + } + + return wp_validate_redirect( $url, $fallback_url ); +} diff --git a/init.php b/init.php index 79119c6132..ff7b4da016 100644 --- a/init.php +++ b/init.php @@ -10,7 +10,7 @@ * Plugin Name: Pods - Custom Content Types and Fields * Plugin URI: https://pods.io/ * Description: Pods is a framework for creating, managing, and deploying customized content types and fields - * Version: 3.2.1 + * Version: 3.2.1.1 * Author: Pods Framework Team * Author URI: https://pods.io/about/ * Text Domain: pods @@ -43,7 +43,7 @@ add_action( 'init', 'pods_deactivate_pods_ui' ); } else { // Current version. - define( 'PODS_VERSION', '3.2.1' ); + define( 'PODS_VERSION', '3.2.1.1' ); // Current database version, this is the last version the database changed. define( 'PODS_DB_VERSION', '2.3.5' ); diff --git a/package.json b/package.json index 1dd980dc24..00730c5add 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "pods", - "version": "3.2.1", + "version": "3.2.1.1", "description": "Pods is a development framework for creating, extending, managing, and deploying customized content types in WordPress.", "author": "Pods Foundation, Inc", "homepage": "https://pods.io/", diff --git a/readme.txt b/readme.txt index 3b589b0bd6..b304913857 100644 --- a/readme.txt +++ b/readme.txt @@ -5,7 +5,7 @@ Tags: pods, custom post types, custom taxonomies, content types, custom fields Requires at least: 6.0 Tested up to: 6.5 Requires PHP: 7.2 -Stable tag: 3.2.1 +Stable tag: 3.2.1.1 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html @@ -182,6 +182,12 @@ Pods really wouldn't be where it is without all the contributions from our [dono == Changelog == += 3.2.1.1 - May 8th, 2024 = + +*Security Release* + +* Security hardening: Enforce safe URLs for Pods form submission confirmation page URLs. Props to the wesley (wcraft) / Wordfence for responsibly reporting this. (@sc0ttkclark) + = 3.2.1 - March 29th, 2024 = * Performance: The Advanced Filters popup now uses Autocomplete for relationship fields to improve performance for large itemsets. FYI filters are a feature in the Manage Content UI for Advanced Content Types only. (@sc0ttkclark) diff --git a/src/Pods/Blocks/API.php b/src/Pods/Blocks/API.php index 505057e335..cb4edbc53b 100644 --- a/src/Pods/Blocks/API.php +++ b/src/Pods/Blocks/API.php @@ -144,6 +144,11 @@ public function register_assets() { */ $blocks_config = (array) apply_filters( 'pods_blocks_api_config', $blocks_config ); + // Sanitize callbackUrl for security. + foreach ( $blocks_config['commands'] as $key => $command ) { + $blocks_config['commands'][ $key ]['callbackUrl'] = pods_enforce_safe_url( (string) $command['callbackUrl'] ); + } + wp_localize_script( 'pods-blocks-api', 'podsBlocksConfig', $blocks_config ); wp_enqueue_style( 'pods-styles' ); diff --git a/ui/front/form.php b/ui/front/form.php index 8c7ccbaf7e..e96bd1cc1c 100644 --- a/ui/front/form.php +++ b/ui/front/form.php @@ -102,7 +102,7 @@ action="" method="post" class="pods-submittable pods-form pods-form-front pods-form-pod- pods-submittable-ajax" - data-location="" + data-location="" id="pods-form-" data-pods-pod-name="" data-pods-item-id=""