From d591f26ce7830e2b4d48ccbab4ed455f8142db12 Mon Sep 17 00:00:00 2001 From: Pascal Birchler Date: Sat, 9 Jan 2016 14:36:26 +0000 Subject: [PATCH] Ensure `wp_get_referer()` returns `false` when the referrer URL is the current URL. Adds unit tests. Fixes #19856. Built from https://develop.svn.wordpress.org/trunk@36242 git-svn-id: http://core.svn.wordpress.org/trunk@36209 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-includes/functions.php | 4 +++- wp-includes/version.php | 2 +- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/wp-includes/functions.php b/wp-includes/functions.php index be0113254e..6dbc510af5 100644 --- a/wp-includes/functions.php +++ b/wp-includes/functions.php @@ -1525,8 +1525,10 @@ function wp_get_referer() { elseif ( ! empty( $_SERVER['HTTP_REFERER'] ) ) $ref = wp_unslash( $_SERVER['HTTP_REFERER'] ); - if ( $ref && $ref !== wp_unslash( $_SERVER['REQUEST_URI'] ) ) + if ( $ref && $ref !== wp_unslash( $_SERVER['REQUEST_URI'] ) && $ref !== home_url() . wp_unslash( $_SERVER['REQUEST_URI'] ) ) { return wp_validate_redirect( $ref, false ); + } + return false; } diff --git a/wp-includes/version.php b/wp-includes/version.php index b7ba280568..90799aa3b7 100644 --- a/wp-includes/version.php +++ b/wp-includes/version.php @@ -4,7 +4,7 @@ * * @global string $wp_version */ -$wp_version = '4.5-alpha-36241'; +$wp_version = '4.5-alpha-36242'; /** * Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.