diff --git a/plugins/optimization-detective/detect-loader.js b/plugins/optimization-detective/detect-loader.js index a0f8e82a94..13bad0a2f1 100644 --- a/plugins/optimization-detective/detect-loader.js +++ b/plugins/optimization-detective/detect-loader.js @@ -26,13 +26,12 @@ async function load() { } ); } - const argsScript = document.getElementById( - 'optimization-detective-detect-args' - ); + const jsonScriptSelector = 'script#optimization-detective-detect-args'; + const argsScript = document.querySelector( jsonScriptSelector ); if ( ! ( argsScript instanceof HTMLScriptElement ) ) { - throw new Error( 'Missing: SCRIPT#optimization-detective-detect-args' ); + throw new Error( `Missing: ${ jsonScriptSelector }` ); } - const data = JSON.parse( argsScript.textContent ); + const data = JSON.parse( argsScript.text ); if ( ! Array.isArray( data ) || data.length !== 2 || diff --git a/plugins/optimization-detective/load.php b/plugins/optimization-detective/load.php index 119dfc25e7..652a037318 100644 --- a/plugins/optimization-detective/load.php +++ b/plugins/optimization-detective/load.php @@ -5,7 +5,7 @@ * Description: Provides a framework for leveraging real user metrics to detect optimizations for improving page performance. * Requires at least: 6.9 * Requires PHP: 7.4 - * Version: 1.0.0-beta5 + * Version: 1.0.0-beta6 * Author: WordPress Performance Team * Author URI: https://make.wordpress.org/performance/ * License: GPLv2 or later @@ -73,7 +73,7 @@ static function ( string $global_var_name, string $version, Closure $load ): voi } )( 'optimization_detective_pending_plugin', - '1.0.0-beta5', + '1.0.0-beta6', static function ( string $version ): void { if ( defined( 'OPTIMIZATION_DETECTIVE_VERSION' ) ) { return; diff --git a/plugins/optimization-detective/readme.txt b/plugins/optimization-detective/readme.txt index 230de37c5d..31df6fbdd1 100644 --- a/plugins/optimization-detective/readme.txt +++ b/plugins/optimization-detective/readme.txt @@ -2,7 +2,7 @@ Contributors: wordpressdotorg Tested up to: 7.0 -Stable tag: 1.0.0-beta5 +Stable tag: 1.0.0-beta6 License: GPLv2 or later License URI: https://www.gnu.org/licenses/gpl-2.0.html Tags: performance, optimization, rum @@ -55,6 +55,12 @@ The [plugin source code](https://github.com/WordPress/performance/tree/trunk/plu == Changelog == += 1.0.0-beta6 = + +**Security** + +* Add validation of the SCRIPT element containing the detection args JSON. This fixes a DOM clobbering vulnerability in which an injected element with a colliding `id` could shadow the script and cause an arbitrary module to be imported, which required an authenticated user with at least a contributor role. Props to Asaf Mozes (amosec) for [responsible disclosure](https://github.com/WordPress/performance/blob/trunk/SECURITY.md). + = 1.0.0-beta5 = **Bug Fixes**