From 62baca7bd3ec7f66edabfec45a8ade16bd5e8eeb Mon Sep 17 00:00:00 2001 From: Intenzi Date: Wed, 30 Sep 2026 17:45:59 +0530 Subject: [PATCH 1/2] fix: strictly validate file extension and remove MIME type regex fallback in is_valid_type - Prevents arbitrary file extensions to bypass validation --- .../controllers/upload/processors/RTMediaUploadFile.php | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/app/main/controllers/upload/processors/RTMediaUploadFile.php b/app/main/controllers/upload/processors/RTMediaUploadFile.php index 575469b2a..67c817a19 100755 --- a/app/main/controllers/upload/processors/RTMediaUploadFile.php +++ b/app/main/controllers/upload/processors/RTMediaUploadFile.php @@ -249,10 +249,8 @@ public function is_valid_type( $file ) { ); $allowed_types = explode( ',', $allowed_types[0]['extensions'] ); - if ( false === in_array( strtolower( $file_data['ext'] ), $allowed_types, true ) ) { - if ( ! preg_match( '/' . implode( '|', $allowed_types ) . '/i', $file['type'], $result ) || ! isset( $result[0] ) ) { - throw new RTMediaUploadException( UPLOAD_ERR_EXTENSION ); - } + if ( empty( $file_data['ext'] ) || false === in_array( strtolower( $file_data['ext'] ), $allowed_types, true ) ) { + throw new RTMediaUploadException( UPLOAD_ERR_EXTENSION ); } } catch ( RTMediaUploadException $e ) { echo esc_html( $e->getMessage() ); From 90fdb0c7320d31ade21d2eecb910a06611d0d7e7 Mon Sep 17 00:00:00 2001 From: Intenzi Date: Wed, 30 Sep 2026 19:02:16 +0530 Subject: [PATCH 2/2] fix: restrict file uploads to standard multipart $_FILES to prevent arbitrary sideloading - Prevents arbitrary server file paths from being processed via wp_handle_sideload --- .../upload/processors/RTMediaUploadFile.php | 13 +++---------- 1 file changed, 3 insertions(+), 10 deletions(-) diff --git a/app/main/controllers/upload/processors/RTMediaUploadFile.php b/app/main/controllers/upload/processors/RTMediaUploadFile.php index 67c817a19..093db69bb 100755 --- a/app/main/controllers/upload/processors/RTMediaUploadFile.php +++ b/app/main/controllers/upload/processors/RTMediaUploadFile.php @@ -72,7 +72,7 @@ public function process() { include_once ABSPATH . 'wp-admin/includes/file.php'; include_once ABSPATH . 'wp-admin/includes/image.php'; - $upload_type = $this->fake ? 'wp_handle_sideload' : 'wp_handle_upload'; + $upload_type = 'wp_handle_upload'; // todo why use $rt_set_filter_uplaod_dir global variable if we can remove filter for upload_dir after upload finish. global $rt_set_filter_uplaod_dir; @@ -173,16 +173,9 @@ public function upload_dir( $upload_dir ) { */ public function set_file( $files ) { /** - * If files parameter is provided then take th file details from that object + * Check for $_FILES global object from the form submitted */ - if ( $files ) { - - $this->fake = true; - $this->populate_file_array( (array) $this->uploaded['files'] ); - /** - * Otherwise check for $_FILES global object from the form submitted - */ - } elseif ( isset( $_FILES['rtmedia_file'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing -- We are just checking if the value exists over here. + if ( isset( $_FILES['rtmedia_file'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Missing -- We are just checking if the value exists over here. $this->populate_file_array( array_map( 'sanitize_text_field', $_FILES['rtmedia_file'] ) ); // phpcs:ignore WordPress.Security.NonceVerification.Missing -- We are just checking if the value exists over here. // The function populate_file_array is sanitizing string and integer values. } else {