Skip to content

Version update v4.7.14 - #2376

Merged
Pradeep1308 merged 14 commits into
masterfrom
develop
Oct 6, 2026
Merged

Pradeep1308 merged 14 commits into
masterfrom
develop

Conversation

@Intenzi

@Intenzi Intenzi commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Changelog

  • FIXED
    • Fixed file upload handling to prevent arbitrary file sideloading.
    • Fixed file extension validation to enforce allowed media extensions strictly.
    • Fixed album permission checks when moving media to another album.
    • Fixed media edit sanitization to prevent unauthorized attribute modifications.
    • Fixed media privacy level validation against allowed values.
    • Fixed privacy modification checks on single media and album edit forms.

Intenzi and others added 9 commits September 29, 2026 18:31
Fix - Enforce Album permissions, allowlist, sanitization on media edit
…back in is_valid_type

- Prevents arbitrary file extensions to bypass validation
…rbitrary sideloading

- Prevents arbitrary server file paths from being processed via wp_handle_sideload
Fix - Restrict file upload sideloading and enforce extension validation

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The upload hardening unintentionally breaks the public programmatic file-upload path.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Updates rtMedia to v4.7.14 with security hardening for uploads, media edits, album permissions, and privacy validation.

Changes:

  • Restricts upload handling and file extensions.
  • Tightens media-edit, album, and privacy validation.
  • Updates release metadata, changelogs, and translation templates.
File Description
readme.txt Updates release metadata and notes.
README.md Adds contributor and changelog updates.
languages/​buddypress-media.pot Regenerates translation metadata.
languages/​buddpress-media.pot Regenerates legacy translation template.
index.php Bumps plugin version.
changelog.txt Documents v4.7.14 fixes.
app/​main/​controllers/​upload/​RTMediaUploadEndpoint.php Sanitizes activity privacy.
app/​main/​controllers/​upload/​processors/​RTMediaUploadFile.php Hardens upload and extension handling.
app/​main/​controllers/​template/​RTMediaTemplate.php Validates album destinations.
app/​main/​controllers/​template/​rtmedia-functions.php Restricts editable fields and privacy values.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

include_once ABSPATH . 'wp-admin/includes/image.php';

$upload_type = $this->fake ? 'wp_handle_sideload' : 'wp_handle_upload';
$upload_type = 'wp_handle_upload';

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This can be dismissed. wp_handle_sideload was deliberately removed to prevent arbitrary server file sideloading vulnerabilities via client-supplied paths, as recommended by security intelligence. All legitimate rtMedia uploads (UI, activity, and AJAX) operate strictly via standard multipart $_FILES['rtmedia_file'] through wp_handle_upload. Furthermore, rtmedia_add_media() is not utilized internally anywhere in the plugin.

@the-hercules

Copy link
Copy Markdown
Contributor

Could you please look into whether this is valid?

save_single_edit() and save_album_edit() currently allow the privacy value to pass through even when the edit form hides the privacy field.

This seems to allow crafted requests to change privacy for:

  • Group media
  • Moderated media (privacy = 80)
  • Comment media
  • Cases where users are not allowed to set privacy

Since the PR changes this area and the changelog mentions privacy validation, I think it may be worth checking whether privacy should only be accepted under the same conditions where the edit form exposes the field.

This appears to predate the PR, so just something worth looking into.

@Intenzi

Intenzi commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

I have identified that it is an issue that needs resolution. I am providing a fix and will raise a PR for it, tag you there.

@Intenzi

Intenzi commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

I have raised #2378 to resolve the identified vulnerability.

@rtBot

rtBot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Unable to PHPCS or SVG scan one or more files due to error running PHPCS/SVG scanner:

  • app/main/controllers/template/RTMediaTemplate.php
  • app/main/controllers/template/rtmedia-functions.php
  • app/main/controllers/upload/RTMediaUploadEndpoint.php
  • app/main/controllers/upload/processors/RTMediaUploadFile.php
  • index.php

The error may be temporary. If the error persists, please contact a human (commit-ID: 88592bc).

@Pradeep1308
Pradeep1308 merged commit 26b7a2a into master Oct 6, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants