Commit 89a322a75f for wordpress.org
commit 89a322a75f49db982667b3c7bfde274b60d9d177
Author: jorbin <jorbin@git.wordpress.org>
Date: Tue Oct 6 14:49:45 2026 +0000
Export: Ensure post IDs are integers when building a WXR export.
Props xknown, vortfu, marcs0h, lancewillett.
Built from https://develop.svn.wordpress.org/trunk@64129
git-svn-id: http://core.svn.wordpress.org/trunk@63285 1a063a9b-81f0-0310-95a4-ce76da25c4cd
diff --git a/wp-admin/includes/export.php b/wp-admin/includes/export.php
index a77cb804f0..aa3753cb24 100644
--- a/wp-admin/includes/export.php
+++ b/wp-admin/includes/export.php
@@ -183,11 +183,15 @@ function export_wp( $args = array() ) {
)
);
+ // Cast thumbnail IDs to integers to prevent second-order SQL injection via user-controlled meta values.
+ $thumbnails_ids = array_filter( array_map( 'absint', $thumbnails_ids ) );
+
$additional_ids = array_merge( $additional_ids, $attachment_ids, $thumbnails_ids );
}
- // Merge the additional IDs back with the original post IDs after processing all posts
- $post_ids = array_unique( array_merge( $post_ids, $additional_ids ) );
+ // Merge the additional IDs back with the original post IDs after processing all posts.
+ // Cast to integers as defense-in-depth, since $additional_ids may include values sourced from postmeta.
+ $post_ids = array_unique( array_map( 'absint', array_merge( $post_ids, $additional_ids ) ) );
}
/*
@@ -597,8 +601,10 @@ function export_wp( $args = array() ) {
// Fetch 20 posts at a time rather than loading the entire table into memory.
while ( $next_posts = array_splice( $post_ids, 0, 20 ) ) {
- $where = 'WHERE ID IN (' . implode( ',', $next_posts ) . ')';
- $posts = $wpdb->get_results( "SELECT * FROM {$wpdb->posts} $where" );
+ // Re-sanitize immediately before use, as defense-in-depth against the IDs being interpolated directly into SQL below.
+ $next_posts = array_map( 'absint', $next_posts );
+ $where = 'WHERE ID IN (' . implode( ',', $next_posts ) . ')';
+ $posts = $wpdb->get_results( "SELECT * FROM {$wpdb->posts} $where" );
// Begin Loop.
foreach ( $posts as $post ) {
diff --git a/wp-includes/version.php b/wp-includes/version.php
index dad3ea8c2c..4153773607 100644
--- a/wp-includes/version.php
+++ b/wp-includes/version.php
@@ -16,7 +16,7 @@
*
* @global string $wp_version
*/
-$wp_version = '7.2-alpha-64128';
+$wp_version = '7.2-alpha-64129';
/**
* Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.