Post status enum is ignored in collection params, allowing invalid values
|Reported by:||joehoyle||Owned by:||joehoyle|
Originally reported at https://github.com/WP-API/WP-API/issues/2889, currently the post status in /wp/v2/posts?status=invalid does not throw an error and is passed to WP_Query, resulting in all post statuses being returned.
Note: this does not affect unauthenticated users, as we whitelist those types, so there's no permissions / information disclosure here.
Proposed fix in https://github.com/danielbachhuber/wordpress-develop/pull/4
Change History (6)
- Owner set to joehoyle
- Resolution set to fixed
- Status changed from new to closed