Skip to content

Fix - Restrict file upload sideloading and enforce extension validation - #2374

Merged
Intenzi merged 2 commits into
developfrom
fix/upload-security-fixes
Oct 1, 2026
Merged

Intenzi merged 2 commits into
developfrom
fix/upload-security-fixes

Conversation

@Intenzi

@Intenzi Intenzi commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Summary

Addresses arbitrary server-side file sideloading and file extension validation bypass vulnerabilities in media upload requests.

Changes

  1. Removed Sideloading: Removed the legacy $this->fake branch in RTMediaUploadFile::set_file() and enforced $upload_type = 'wp_handle_upload' in RTMediaUploadFile::process().

    • Reason: Accepting client-supplied files descriptors from $_POST forwarded arbitrary server file paths (tmp_name) to wp_handle_sideload(). Legitimate plugin uploads use PHP's authentic $_FILES['rtmedia_file'] stream. It does not affect any existing functionality.
  2. Removed MIME Regex Check: Removed the fallback preg_match on $file['type'] in RTMediaUploadFile::is_valid_type(), enforcing strict extension validation against $allowed_types.

    • Reason: The fallback checked $file['type'] instead of rejecting unauthorized extensions.

…back in is_valid_type

- Prevents arbitrary file extensions to bypass validation
…rbitrary sideloading

- Prevents arbitrary server file paths from being processed via wp_handle_sideload
@Intenzi Intenzi self-assigned this Sep 30, 2026
@Intenzi Intenzi added the bug label Sep 30, 2026
@rtBot

rtBot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Unable to PHPCS or SVG scan one or more files due to error running PHPCS/SVG scanner:

  • app/main/controllers/upload/processors/RTMediaUploadFile.php

The error may be temporary. If the error persists, please contact a human (commit-ID: 90fdb0c).

@Intenzi
Intenzi merged commit cf899ec into develop Oct 1, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants