Make WordPress Core

Ticket #41983: 41983.patch

File 41983.patch, 4.0 KB (added by johnjamesjacoby, 7 years ago)
  • src/wp-admin/includes/class-wp-importer.php

    diff --git src/wp-admin/includes/class-wp-importer.php src/wp-admin/includes/class-wp-importer.php
    index b9f652b..c5d400b 100644
     
    2929                // Grab all posts in chunks
    3030                do {
    3131                        $meta_key = $importer_name . '_' . $bid . '_permalink';
    32                         $sql = $wpdb->prepare( "SELECT post_id, meta_value FROM $wpdb->postmeta WHERE meta_key = '%s' LIMIT %d,%d", $meta_key, $offset, $limit );
     32                        $sql = $wpdb->prepare( "SELECT post_id, meta_value FROM $wpdb->postmeta WHERE meta_key = %s LIMIT %d,%d", $meta_key, $offset, $limit );
    3333                        $results = $wpdb->get_results( $sql );
    3434
    3535                        // Increment offset
  • src/wp-admin/includes/nav-menu.php

    diff --git src/wp-admin/includes/nav-menu.php src/wp-admin/includes/nav-menu.php
    index a6aac33..9c4c6fb 100644
     
    996996        $delete_timestamp = time() - ( DAY_IN_SECONDS * EMPTY_TRASH_DAYS );
    997997
    998998        // Delete orphaned draft menu items.
    999         $menu_items_to_delete = $wpdb->get_col($wpdb->prepare("SELECT ID FROM $wpdb->posts AS p LEFT JOIN $wpdb->postmeta AS m ON p.ID = m.post_id WHERE post_type = 'nav_menu_item' AND post_status = 'draft' AND meta_key = '_menu_item_orphaned' AND meta_value < '%d'", $delete_timestamp ) );
     999        $menu_items_to_delete = $wpdb->get_col($wpdb->prepare("SELECT ID FROM $wpdb->posts AS p LEFT JOIN $wpdb->postmeta AS m ON p.ID = m.post_id WHERE post_type = 'nav_menu_item' AND post_status = 'draft' AND meta_key = '_menu_item_orphaned' AND meta_value < %d", $delete_timestamp ) );
    10001000
    10011001        foreach ( (array) $menu_items_to_delete as $menu_item_id )
    10021002                wp_delete_post( $menu_item_id, true );
  • src/wp-includes/functions.php

    diff --git src/wp-includes/functions.php src/wp-includes/functions.php
    index 2559613..df50de9 100644
     
    48044804
    48054805        $delete_timestamp = time() - ( DAY_IN_SECONDS * EMPTY_TRASH_DAYS );
    48064806
    4807         $posts_to_delete = $wpdb->get_results($wpdb->prepare("SELECT post_id FROM $wpdb->postmeta WHERE meta_key = '_wp_trash_meta_time' AND meta_value < '%d'", $delete_timestamp), ARRAY_A);
     4807        $posts_to_delete = $wpdb->get_results($wpdb->prepare("SELECT post_id FROM $wpdb->postmeta WHERE meta_key = '_wp_trash_meta_time' AND meta_value < %d", $delete_timestamp), ARRAY_A);
    48084808
    48094809        foreach ( (array) $posts_to_delete as $post ) {
    48104810                $post_id = (int) $post['post_id'];
     
    48214821                }
    48224822        }
    48234823
    4824         $comments_to_delete = $wpdb->get_results($wpdb->prepare("SELECT comment_id FROM $wpdb->commentmeta WHERE meta_key = '_wp_trash_meta_time' AND meta_value < '%d'", $delete_timestamp), ARRAY_A);
     4824        $comments_to_delete = $wpdb->get_results($wpdb->prepare("SELECT comment_id FROM $wpdb->commentmeta WHERE meta_key = '_wp_trash_meta_time' AND meta_value < %d", $delete_timestamp), ARRAY_A);
    48254825
    48264826        foreach ( (array) $comments_to_delete as $comment ) {
    48274827                $comment_id = (int) $comment['comment_id'];
  • src/wp-includes/taxonomy.php

    diff --git src/wp-includes/taxonomy.php src/wp-includes/taxonomy.php
    index 87fe0eb..413b92d 100644
     
    37853785                        INNER JOIN {$wpdb->postmeta} AS m2 ON ( m2.post_id = m1.post_id )
    37863786                        INNER JOIN {$wpdb->postmeta} AS m3 ON ( m3.post_id = m1.post_id )
    37873787                WHERE ( m1.meta_key = '_menu_item_type' AND m1.meta_value = 'taxonomy' )
    3788                         AND ( m2.meta_key = '_menu_item_object' AND m2.meta_value = '%s' )
     3788                        AND ( m2.meta_key = '_menu_item_object' AND m2.meta_value = %s )
    37893789                        AND ( m3.meta_key = '_menu_item_object_id' AND m3.meta_value = %d )",
    37903790                $taxonomy,
    37913791                $term_id
  • src/wp-includes/wp-db.php

    diff --git src/wp-includes/wp-db.php src/wp-includes/wp-db.php
    index 9d125d0..c601bca 100644
     
    12671267         *     $wild = '%';
    12681268         *     $find = 'only 43% of planets';
    12691269         *     $like = $wild . $wpdb->esc_like( $find ) . $wild;
    1270          *     $sql  = $wpdb->prepare( "SELECT * FROM $wpdb->posts WHERE post_content LIKE '%s'", $like );
     1270         *     $sql  = $wpdb->prepare( "SELECT * FROM $wpdb->posts WHERE post_content LIKE %s", $like );
    12711271         *
    12721272         * Example Escape Chain:
    12731273         *