| Server IP : 91.134.83.25 / Your IP : 216.73.216.193 Web Server : Apache System : Linux plesk.serveurapc.fr 6.1.0-51-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.177-1 (2026-07-16) x86_64 User : marrasse ( 10057) PHP Version : 8.2.32 Disable Function : opcache_get_status MySQL : OFF | cURL : ON | WGET : OFF | Perl : OFF | Python : OFF | Sudo : OFF | Pkexec : OFF Directory : /var/www/vhosts/as-cp.fr/quarantine_extra_20260721/ |
Upload File : |
<?php
/*
Plugin Name: WP Security Hardening
Description: Mitigates REST API batch route confusion (CVE-2026-63030) and author__not_in SQLi (CVE-2026-60137).
Version: 1.0.0
Author: WordPress Security
*/
add_filter('rest_pre_dispatch', function($result, $server, $request) {
if ($result !== null) return $result;
$route = $request->get_route();
if (preg_match('#/v2/batch\b#i', $route) && !current_user_can('read')) {
return new WP_Error(
'rest_batch_forbidden',
'Batch endpoint requires authentication.',
array('status' => 403)
);
}
return $result;
}, 5, 3);
add_action('pre_get_posts', function($query) {
if (!empty($query->query_vars['author__not_in'])) {
$query->query_vars['author__not_in'] = array_map('absint',
(array) $query->query_vars['author__not_in']);
}
});