Commit 89a322a75f for wordpress.org

commit 89a322a75f49db982667b3c7bfde274b60d9d177
Author: jorbin <jorbin@git.wordpress.org>
Date:   Tue Oct 6 14:49:45 2026 +0000

    Export: Ensure post IDs are integers when building a WXR export.

    Props xknown, vortfu, marcs0h, lancewillett.

    Built from https://develop.svn.wordpress.org/trunk@64129


    git-svn-id: http://core.svn.wordpress.org/trunk@63285 1a063a9b-81f0-0310-95a4-ce76da25c4cd

diff --git a/wp-admin/includes/export.php b/wp-admin/includes/export.php
index a77cb804f0..aa3753cb24 100644
--- a/wp-admin/includes/export.php
+++ b/wp-admin/includes/export.php
@@ -183,11 +183,15 @@ function export_wp( $args = array() ) {
 				)
 			);

+			// Cast thumbnail IDs to integers to prevent second-order SQL injection via user-controlled meta values.
+			$thumbnails_ids = array_filter( array_map( 'absint', $thumbnails_ids ) );
+
 			$additional_ids = array_merge( $additional_ids, $attachment_ids, $thumbnails_ids );
 		}

-		// Merge the additional IDs back with the original post IDs after processing all posts
-		$post_ids = array_unique( array_merge( $post_ids, $additional_ids ) );
+		// Merge the additional IDs back with the original post IDs after processing all posts.
+		// Cast to integers as defense-in-depth, since $additional_ids may include values sourced from postmeta.
+		$post_ids = array_unique( array_map( 'absint', array_merge( $post_ids, $additional_ids ) ) );
 	}

 	/*
@@ -597,8 +601,10 @@ function export_wp( $args = array() ) {

 		// Fetch 20 posts at a time rather than loading the entire table into memory.
 		while ( $next_posts = array_splice( $post_ids, 0, 20 ) ) {
-			$where = 'WHERE ID IN (' . implode( ',', $next_posts ) . ')';
-			$posts = $wpdb->get_results( "SELECT * FROM {$wpdb->posts} $where" );
+			// Re-sanitize immediately before use, as defense-in-depth against the IDs being interpolated directly into SQL below.
+			$next_posts = array_map( 'absint', $next_posts );
+			$where      = 'WHERE ID IN (' . implode( ',', $next_posts ) . ')';
+			$posts      = $wpdb->get_results( "SELECT * FROM {$wpdb->posts} $where" );

 			// Begin Loop.
 			foreach ( $posts as $post ) {
diff --git a/wp-includes/version.php b/wp-includes/version.php
index dad3ea8c2c..4153773607 100644
--- a/wp-includes/version.php
+++ b/wp-includes/version.php
@@ -16,7 +16,7 @@
  *
  * @global string $wp_version
  */
-$wp_version = '7.2-alpha-64128';
+$wp_version = '7.2-alpha-64129';

 /**
  * Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.