Skip to content

Do not print add_query_arg directly#3

Open
rips-hb wants to merge 1 commit into
bonny:masterfrom
rips-hb:master
Open

Do not print add_query_arg directly#3
rips-hb wants to merge 1 commit into
bonny:masterfrom
rips-hb:master

Conversation

@rips-hb

@rips-hb rips-hb commented Aug 28, 2018

Copy link
Copy Markdown

Hi Pär,

you may have seen the discussion at https://wordpress.org/support/topic/this-plugin-has-a-worryingly-high-coderisk-rips-score/ already. The problem occurs because the return value of add_query_arg is printed directly and it contains user input, so it is reported as a XSS vulnerability. Since there is a NONCE check the real security risk should be pretty low but I think it is still a good idea to resolve this. As a quick fix I just encode the value with Base64. A cleaner patch would be to return JSON (and very importantly, the json content type) and parse that instead.

Best regards,
Hendrik

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant