Skip to content

fix/WPS-7849-vulnerability-issue-fix - #310

Open
Stuti-Cedcoss wants to merge 1 commit into
release/v2.1.0from
fix/WPS-7849-vulnerabilty-issue-fix
Open

Stuti-Cedcoss wants to merge 1 commit into
release/v2.1.0from
fix/WPS-7849-vulnerabilty-issue-fix

Conversation

@Stuti-Cedcoss

Copy link
Copy Markdown
Collaborator

Task Link

WPS-7849

Summary

Fix three security vulnerabilities (REST API auth bypass, CSRF on cancel, membership restriction bypass via excerpt) plus a new Retry Renewal Payment admin order action. Version bumped to 2.0.3.

Changes Made

  • CVE-1 (REST API auth bypass): wps_sfw_validate_secretkey() — trim both keys, reject empty, use hash_equals() for constant-time comparison
  • CVE-2 (CSRF on subscription cancel): wps_sfw_cancel_susbcription() — added wp_verify_nonce() keyed to subscription ID + status
  • CVE-3 (Membership restriction bypass): Removed is_singular() guard from maybe_restrict_content(); added maybe_restrict_excerpt() hooked to the_excerpt
  • Admin UX: Added "Retry Renewal Payment" order action for failed renewal orders
  • Tests: New RestApiAuthTest.php (12 cases); 6 new/updated cases in RestrictionEnforcerTest.php
  • Version: 2.0.2 → 2.0.3

Testing

  • Tested locally: No
  • Edge cases covered:
    • Whitespace-only API key rejected
    • Empty stored key rejects all supplied keys
    • Forged cancel nonce rejected
    • Restricted excerpt returns empty for guests via REST
    • Members still receive their excerpt
    • Product-kind rules do not block excerpts
    • Retry action only visible on failed renewal orders

Screenshots / Demo (if applicable)

Checklist

  • Code reviewed by self
  • No unnecessary code
  • Proper naming conventions

CVE-1 (REST API auth bypass): wps_sfw_validate_secretkey() now trims both
values and rejects empty strings before hash_equals(), preventing whitespace-
only consumer_secret from bypassing authentication.

CVE-2 (CSRF + missing ownership on cancel): wps_sfw_cancel_susbcription()
now calls wp_verify_nonce() and wps_sfw_current_user_can_view_subscription()
before acting, blocking forged and cross-user cancellation requests.

CVE-3 (membership restriction bypass via REST/feed): maybe_restrict_content()
now falls through to the restriction message for redirect-behavior rules in
REST API and feed contexts (where template_redirect never fires).
maybe_filter_archive() now also excludes restricted posts from REST API
collection queries (which are not the WP global main query).

Tests: add CancelSubscriptionTest covering nonce and ownership cases; extend
RestrictionEnforcerTest with redirect-in-REST, redirect-in-feed, and
archive-filter-REST scenarios.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant