Make WordPress Core

Opened 4 months ago

#62224 new enhancement

The class class-wp-theme-json.php methods compute_theme_vars and to_ruleset need to be hardened

Reported by: villu164's profile villu164 Owned by:
Milestone: Awaiting Review Priority: normal
Severity: normal Version: 6.6.2
Component: Themes Keywords:
Focuses: Cc:


I first reported the issue on HackerOne and was told this can be a public hardening ticket. (

The compute_theme_vars ( and to_ruleset ( need to be hardened and the theme.json, should be considered as user supplied content. Thus the before-mentioned methods need to adjust for that and use proper sanitization

Change History (0)

Note: See TracTickets for help on using tickets.