From 031cbb0548fcf0212b8f8136fdba0e9d119f7b84 Mon Sep 17 00:00:00 2001 From: Pascal Birchler Date: Tue, 16 May 2017 08:17:34 +0000 Subject: [PATCH] Whitelist post arguments in XML-RPC Merges [40677] to the 4.7 branch. Built from https://develop.svn.wordpress.org/branches/4.7@40678 git-svn-id: http://core.svn.wordpress.org/branches/4.7@40541 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-includes/class-wp-xmlrpc-server.php | 30 ++++++++++++++++++++------ wp-includes/version.php | 2 +- 2 files changed, 25 insertions(+), 7 deletions(-) diff --git a/wp-includes/class-wp-xmlrpc-server.php b/wp-includes/class-wp-xmlrpc-server.php index 5084da65cb..7bbde05c2b 100644 --- a/wp-includes/class-wp-xmlrpc-server.php +++ b/wp-includes/class-wp-xmlrpc-server.php @@ -1295,10 +1295,31 @@ class wp_xmlrpc_server extends IXR_Server { * @return IXR_Error|string */ protected function _insert_post( $user, $content_struct ) { - $defaults = array( 'post_status' => 'draft', 'post_type' => 'post', 'post_author' => 0, - 'post_password' => '', 'post_excerpt' => '', 'post_content' => '', 'post_title' => '' ); + $defaults = array( + 'post_status' => 'draft', + 'post_type' => 'post', + 'post_author' => null, + 'post_password' => null, + 'post_excerpt' => null, + 'post_content' => null, + 'post_title' => null, + 'post_date' => null, + 'post_date_gmt' => null, + 'post_format' => null, + 'post_name' => null, + 'post_thumbnail' => null, + 'post_parent' => null, + 'ping_status' => null, + 'comment_status' => null, + 'custom_fields' => null, + 'terms_names' => null, + 'terms' => null, + 'sticky' => null, + 'enclosure' => null, + 'ID' => null, + ); - $post_data = wp_parse_args( $content_struct, $defaults ); + $post_data = wp_parse_args( array_intersect_key( $content_struct, $defaults ), $defaults ); $post_type = get_post_type_object( $post_data['post_type'] ); if ( ! $post_type ) @@ -1488,9 +1509,6 @@ class wp_xmlrpc_server extends IXR_Server { $post_data['tax_input'] = $terms; unset( $post_data['terms'], $post_data['terms_names'] ); - } else { - // Do not allow direct submission of 'tax_input', clients must use 'terms' and/or 'terms_names'. - unset( $post_data['tax_input'], $post_data['post_category'], $post_data['tags_input'] ); } if ( isset( $post_data['post_format'] ) ) { diff --git a/wp-includes/version.php b/wp-includes/version.php index 49cd320fa1..0a894bcdff 100644 --- a/wp-includes/version.php +++ b/wp-includes/version.php @@ -4,7 +4,7 @@ * * @global string $wp_version */ -$wp_version = '4.7.5-alpha-40616'; +$wp_version = '4.7.5-alpha-40678'; /** * Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.