Make WordPress Core


Ignore:
Timestamp:
08/06/2026 07:54:07 PM (7 weeks ago)
Author:
desrosj
Message:

Security: Backport the WordPress 7.0.3 security fixes to the 5.0 branch.

  • Users: Ensure a proper email address is used before sending email confirmations.
  • Formatting: Prevent stack overflow in safecss_filter_attr.
  • Multisite: Enforce the active signup policy for existing users.
  • HTTP API: Improve compliance with IPv4 Special-Purpose Address Space.
  • Users: Prevent Usernames from mangling HTML
  • Canonical: Only redirect for publicly viewable post types.
  • Administration: When wp_is_large_user_count(), ensure that the post author is always added to author dropdown.

Merges [63060],[63061],[63062],[63063],[63064],[63065],[63067] to the 5.0 branch.

Props xknown, westonruter, jeremyfelt, peterwilsoncc, paulkevan, lucasbustamante, jorbin, desrosj, vortfu, dmsnell, johnbillion, ehtis, batmoo, lancewillett, jonsurrell.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • branches/5.0/src/wp-admin/includes/user.php

    r43487 r63112  
    4343                $user->user_login = sanitize_user($_POST['user_login'], true);
    4444
     45        $errors = new WP_Error();
     46
    4547        $pass1 = $pass2 = '';
    4648        if ( isset( $_POST['pass1'] ) )
    … …  
    6365        }
    6466
    65         if ( isset( $_POST['email'] ))
    66                 $user->user_email = sanitize_text_field( wp_unslash( $_POST['email'] ) );
     67        if ( isset( $_POST['email'] ) ) {
     68                $maybe_email = wp_unslash( $_POST['email'] );
     69                if ( is_string( $maybe_email ) && is_email( $maybe_email ) ) {
     70                        $user->user_email = $maybe_email;
     71                } else {
     72                        $errors->add( 'invalid_email', __( '<strong>ERROR</strong>: The email address isn&#8217;t correct.' ), array( 'form-field' => 'email' ) );
     73                }
     74        }
    6775        if ( isset( $_POST['url'] ) ) {
    6876                if ( empty ( $_POST['url'] ) || $_POST['url'] == 'http://' ) {
    … …  
    117125        if ( !empty($_POST['use_ssl']) )
    118126                $user->use_ssl = 1;
    119 
    120         $errors = new WP_Error();
    121127
    122128        /* checking that username has been typed */
Note: See TracChangeset for help on using the changeset viewer.