Grouped backports to the 4.2 branch.

- Media: Prevent CSRF setting attachment thumbnails.

Merges [55764] to the 4.2 branch.
Props dd32, isabel_brison, martinkrcho, matveb, ocean90, paulkevan, peterwilsoncc, timothyblynjacobs, xknown, youknowriad.
Built from https://develop.svn.wordpress.org/branches/4.2@55775


git-svn-id: http://core.svn.wordpress.org/branches/4.2@55287 1a063a9b-81f0-0310-95a4-ce76da25c4cd
This commit is contained in:
Sergey Biryukov 2023-05-16 15:24:21 +00:00
parent b932c64484
commit ea65ee36b2
4 changed files with 28 additions and 3 deletions

View File

@ -41,7 +41,27 @@ include( ABSPATH . 'wp-admin/admin-header.php' );
</h2> </h2>
<div class="changelog point-releases"> <div class="changelog point-releases">
<h3><?php echo _n( 'Maintenance and Security Release', 'Maintenance and Security Releases', 34 ); ?></h3> <h3><?php echo _n( 'Maintenance and Security Release', 'Maintenance and Security Releases', 35 ); ?></h3>
<p>
<?php
printf(
/* translators: %s: WordPress version number */
__( '<strong>Version %1$s</strong> addressed a security issue.' ),
'4.2.35'
);
?>
<?php
printf(
/* translators: %s: HelpHub URL */
__( 'For more information, see <a href="%s">the release notes</a>.' ),
sprintf(
/* translators: %s: WordPress version */
esc_url( __( 'https://wordpress.org/support/wordpress-version/version-%s/' ) ),
sanitize_title( '4.2.35' )
)
);
?>
</p>
<p> <p>
<?php <?php
printf( printf(

View File

@ -2024,6 +2024,10 @@ function wp_ajax_set_attachment_thumbnail() {
wp_send_json_error(); wp_send_json_error();
} }
if ( false === check_ajax_referer( 'set-attachment-thumbnail', '_ajax_nonce', false ) ) {
wp_send_json_error();
}
$post_ids = array(); $post_ids = array();
// For each URL, try to find its corresponding post ID. // For each URL, try to find its corresponding post ID.
foreach ( $_POST['urls'] as $url ) { foreach ( $_POST['urls'] as $url ) {

View File

@ -2951,7 +2951,8 @@ function wp_enqueue_media( $args = array() ) {
/** This filter is documented in wp-admin/includes/media.php */ /** This filter is documented in wp-admin/includes/media.php */
'captions' => ! apply_filters( 'disable_captions', '' ), 'captions' => ! apply_filters( 'disable_captions', '' ),
'nonce' => array( 'nonce' => array(
'sendToEditor' => wp_create_nonce( 'media-send-to-editor' ), 'sendToEditor' => wp_create_nonce( 'media-send-to-editor' ),
'setAttachmentThumbnail' => wp_create_nonce( 'set-attachment-thumbnail' ),
), ),
'post' => array( 'post' => array(
'id' => 0, 'id' => 0,

View File

@ -4,7 +4,7 @@
* *
* @global string $wp_version * @global string $wp_version
*/ */
$wp_version = '4.2.34'; $wp_version = '4.2.35';
/** /**
* Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema. * Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.