Repository navigation
Version update v4.7.14 - #2376
Conversation
…t to prevent mass assignment
Fix - Enforce Album permissions, allowlist, sanitization on media edit
…back in is_valid_type - Prevents arbitrary file extensions to bypass validation
…rbitrary sideloading - Prevents arbitrary server file paths from being processed via wp_handle_sideload
Fix - Restrict file upload sideloading and enforce extension validation
Version update v4.7.14
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The upload hardening unintentionally breaks the public programmatic file-upload path.
Review effort: Balanced
Findings: 1
What changed in this PR
Updates rtMedia to v4.7.14 with security hardening for uploads, media edits, album permissions, and privacy validation.
Changes:
- Restricts upload handling and file extensions.
- Tightens media-edit, album, and privacy validation.
- Updates release metadata, changelogs, and translation templates.
| File | Description |
|---|---|
readme.txt |
Updates release metadata and notes. |
README.md |
Adds contributor and changelog updates. |
languages/buddypress-media.pot |
Regenerates translation metadata. |
languages/buddpress-media.pot |
Regenerates legacy translation template. |
index.php |
Bumps plugin version. |
changelog.txt |
Documents v4.7.14 fixes. |
app/main/controllers/upload/RTMediaUploadEndpoint.php |
Sanitizes activity privacy. |
app/main/controllers/upload/processors/RTMediaUploadFile.php |
Hardens upload and extension handling. |
app/main/controllers/template/RTMediaTemplate.php |
Validates album destinations. |
app/main/controllers/template/rtmedia-functions.php |
Restricts editable fields and privacy values. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| include_once ABSPATH . 'wp-admin/includes/image.php'; | ||
|
|
||
| $upload_type = $this->fake ? 'wp_handle_sideload' : 'wp_handle_upload'; | ||
| $upload_type = 'wp_handle_upload'; |
There was a problem hiding this comment.
This can be dismissed. wp_handle_sideload was deliberately removed to prevent arbitrary server file sideloading vulnerabilities via client-supplied paths, as recommended by security intelligence. All legitimate rtMedia uploads (UI, activity, and AJAX) operate strictly via standard multipart $_FILES['rtmedia_file'] through wp_handle_upload. Furthermore, rtmedia_add_media() is not utilized internally anywhere in the plugin.
|
Could you please look into whether this is valid? save_single_edit() and save_album_edit() currently allow the privacy value to pass through even when the edit form hides the privacy field. This seems to allow crafted requests to change privacy for:
Since the PR changes this area and the changelog mentions privacy validation, I think it may be worth checking whether privacy should only be accepted under the same conditions where the edit form exposes the field. This appears to predate the PR, so just something worth looking into. |
|
I have identified that it is an issue that needs resolution. I am providing a fix and will raise a PR for it, tag you there. |
…n UI is not exposed
|
I have raised #2378 to resolve the identified vulnerability. |
Fix - Restrict privacy modification on media and album edit
Update release date, changelog for v4.7.14
|
Unable to PHPCS or SVG scan one or more files due to error running PHPCS/SVG scanner:
The error may be temporary. If the error persists, please contact a human (commit-ID: 88592bc). |

Changelog