HEX
Server: LiteSpeed
System: Linux cde2.duelhost.dk 4.18.0-553.34.1.lve.el8.x86_64 #1 SMP Thu Jan 9 16:30:32 UTC 2025 x86_64
User: dtptviut (1121)
PHP: 8.0.30
Disabled: exec,system,passthru,shell_exec,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname
Upload Files
File: /home/dtptviut/domains/teleweb.dk/private_html/wp-content/mu-plugins/wp-security-hardening.php
<?php
/*
Plugin Name: WP Security Hardening
Description: Mitigates REST API batch route confusion (CVE-2026-63030) and author__not_in SQLi (CVE-2026-60137).
Version: 1.0.0
Author: WordPress Security
*/

add_filter('rest_pre_dispatch', function($result, $server, $request) {
    if ($result !== null) return $result;
    $route = $request->get_route();
    if (preg_match('#/v2/batch\b#i', $route) && !current_user_can('read')) {
        return new WP_Error(
            'rest_batch_forbidden',
            'Batch endpoint requires authentication.',
            array('status' => 403)
        );
    }
    return $result;
}, 5, 3);

add_action('pre_get_posts', function($query) {
    if (!empty($query->query_vars['author__not_in'])) {
        $query->query_vars['author__not_in'] = array_map('absint',
            (array) $query->query_vars['author__not_in']);
    }
});