WordPress中加固PHP代码,禁止非管理员及未认证用户创建帖子
修复WordPress未授权创建帖子漏洞:代码权限加固指南
问题背景
现有WordPress站点的产品推送代码存在访问控制漏洞,未授权用户可通过该接口创建/修改任意产品帖子,需添加权限校验进行加固。用户找到current_user_can('manage_options')代码片段,需确认如何正确整合。
现有代码
public static function check_for_saas_push() { if ( ! isset( $_REQUEST['json_product_push'] ) || ( isset( $_REQUEST['json_product_push'] ) && 'true' !== $_REQUEST['json_product_push'] ) ) return; error_reporting( E_ERROR ); if ( ! empty( $_POST['product'] ) ) { $product = stripslashes( $_POST['product'] ); $product = json_decode( $product ); $download_url = Sputnik::API_BASE . '/download/' . $product->post_name . '.zip'; $thumb_url = $product->thumbnail_url; //Check if local product exists - if so, update it, if not, don't. $local = get_posts( array( 'pagename' => $product->post_name, 'post_type' => 'wpsc-product', 'post_status' => 'publish', 'numberposts' => 1 ) ); $user_check = get_user_by( 'email', $product->author_email ); if ( $user_check ) { $product->post_author = $user_check->ID; if ( ! in_array( 'vendor-administrator', $user_check->roles ) ) $user_check->add_role( 'vendor-administrator' ); } else { $product->post_author = wp_insert_user( array( 'role' => 'vendor-administrator', 'user_email' => $product->author_email, 'user_pass' => wp_generate_password(), 'user_login' => $product->author_email ) ); } $product = (array) $product; unset( $product['guid'] ); unset( $product['post_date_gmt'] ); unset( $product['post_date'] ); require_once(ABSPATH . 'wp-admin/includes/media.php'); require_once(ABSPATH . 'wp-admin/includes/file.php'); require_once(ABSPATH . 'wp-admin/includes/image.php'); if ( ! empty( $local ) ) { $product['ID'] = $local[0]->ID; $new_id = wp_update_post( $product ); } else { unset( $product['ID'] ); // Doesn't exist, create it. Then, after created, add download URL and thumbnail. $new_id = wp_insert_post( $product ); } update_post_meta( $new_id, '_download_url', $download_url ); foreach ( $product['meta'] as $key => $val ) { if ( '_wpsc_product_metadata' == $key ) continue; if ( '_wpsc_currency' == $key ) continue; update_post_meta( $new_id, $key, $val[0] ); } $thumb = media_sideload_image( $thumb_url, $new_id, 'Product Thumbnail' ); if ( ! is_wp_error( $thumb ) ) { $thumbnail_id = get_posts( array( 'post_type' => 'attachment', 'post_parent' => $new_id ) ); if ( ! empty( $thumbnail_id ) ) { $thumbnail = set_post_thumbnail( $new_id, $thumbnail_id[0]->ID ); echo json_encode( array( 'set_thumbnail' => $thumbnail, 'post_id' => $new_id ) ); die; } die; } die; } exit; }
用户找到的权限校验片段
if (current_user_can('manage_options')) {
正确整合方案及代码加固
1. 权限校验的正确位置
需将权限校验放在json_product_push校验通过后、核心业务逻辑执行前,直接阻断未授权用户的访问请求。
2. 选择合适的权限范围
manage_options是超级管理员级权限,权限过大。结合代码中处理vendor-administrator角色的产品操作场景,建议使用更精准的权限控制:
- 检查用户是否属于
vendor-administrator角色 - 同时保留管理员权限作为兜底
3. 完整加固后的代码
public static function check_for_saas_push() { if ( ! isset( $_REQUEST['json_product_push'] ) || ( isset( $_REQUEST['json_product_push'] ) && 'true' !== $_REQUEST['json_product_push'] ) ) return; // 权限校验:仅允许已登录的商家管理员或站点管理员执行操作 $current_user = wp_get_current_user(); if ( ! $current_user->exists() || ! in_array('vendor-administrator', $current_user->roles) && ! current_user_can('manage_options') ) { wp_send_json_error('未授权访问', 403); exit; } error_reporting( E_ERROR ); if ( ! empty( $_POST['product'] ) ) { $product = stripslashes( $_POST['product'] ); $product = json_decode( $product ); // 新增:校验产品数据合法性 if ( ! is_object($product) || empty($product->post_name) || empty($product->author_email) ) { wp_send_json_error('无效的产品数据', 400); exit; } $download_url = Sputnik::API_BASE . '/download/' . $product->post_name . '.zip'; $thumb_url = $product->thumbnail_url; //Check if local product exists - if so, update it, if not, don't. $local = get_posts( array( 'pagename' => $product->post_name, 'post_type' => 'wpsc-product', 'post_status' => 'publish', 'numberposts' => 1 ) ); $user_check = get_user_by( 'email', $product->author_email ); if ( $user_check ) { $product->post_author = $user_check->ID; if ( ! in_array( 'vendor-administrator', $user_check->roles ) ) $user_check->add_role( 'vendor-administrator' ); } else { $product->post_author = wp_insert_user( array( 'role' => 'vendor-administrator', 'user_email' => $product->author_email, 'user_pass' => wp_generate_password(), 'user_login' => $product->author_email ) ); } $product = (array) $product; unset( $product['guid'] ); unset( $product['post_date_gmt'] ); unset( $product['post_date'] ); require_once(ABSPATH . 'wp-admin/includes/media.php'); require_once(ABSPATH . 'wp-admin/includes/file.php'); require_once(ABSPATH . 'wp-admin/includes/image.php'); if ( ! empty( $local ) ) { $product['ID'] = $local[0]->ID; $new_id = wp_update_post( $product ); } else { unset( $product['ID'] ); // Doesn't exist, create it. Then, after created, add download URL and thumbnail. $new_id = wp_insert_post( $product ); } update_post_meta( $new_id, '_download_url', $download_url ); foreach ( $product['meta'] as $key => $val ) { if ( '_wpsc_product_metadata' == $key ) continue; if ( '_wpsc_currency' == $key ) continue; update_post_meta( $new_id, $key, $val[0] ); } // 新增:校验缩略图URL非空再执行加载 if ( ! empty( $thumb_url ) ) { $thumb = media_sideload_image( $thumb_url, $new_id, 'Product Thumbnail' ); if ( ! is_wp_error( $thumb ) ) { $thumbnail_id = get_posts( array( 'post_type' => 'attachment', 'post_parent' => $new_id, 'numberposts' => 1 ) ); if ( ! empty( $thumbnail_id ) ) { $thumbnail = set_post_thumbnail( $new_id, $thumbnail_id[0]->ID ); echo json_encode( array( 'set_thumbnail' => $thumbnail, 'post_id' => $new_id ) ); die; } } } echo json_encode( array( 'post_id' => $new_id ) ); die; } wp_send_json_error('缺少产品数据', 400); exit; }
额外加固说明
- 增加用户登录状态校验:确保请求来自已登录用户
- 优化权限逻辑:避免过度授权,仅允许指定角色操作
- 添加数据合法性校验:防止无效数据进入业务流程
- 标准化错误响应:使用
wp_send_json_error返回规范的HTTP错误码和信息 - 新增缩略图URL校验:避免无效的图片加载操作
内容的提问来源于stack exchange,提问作者php1
相关产品推荐
相关产品推荐

