[wp-trac] [WordPress Trac] #59795: Private Information Exposure via redirect_guess_404_permalink()

WordPress Trac noreply at wordpress.org
Fri Feb 16 23:33:05 UTC 2024


#59795: Private Information Exposure via redirect_guess_404_permalink()
--------------------------------------+----------------------------
 Reporter:  FrancescoCarlucci         |       Owner:  peterwilsoncc
     Type:  defect (bug)              |      Status:  closed
 Priority:  normal                    |   Milestone:  6.5
Component:  Canonical                 |     Version:
 Severity:  minor                     |  Resolution:  fixed
 Keywords:  has-patch has-unit-tests  |     Focuses:  privacy
--------------------------------------+----------------------------
Changes (by peterwilsoncc):

 * status:  assigned => closed
 * resolution:   => fixed


Comment:

 In [changeset:"57645" 57645]:
 {{{
 #!CommitTicketReference repository="" revision="57645"
 Canonical: Limit post types searched by `redirect_guess_404_permalink()`.

 Limit the post types searched in `redirect_guess_404_permalink()` to
 public, searchable post types. This prevents redirects to 404 pages and
 the exposure of private post type slugs.

 Props francescocarlucci, peterwilsoncc, rajinsharwar.
 Fixes #59795.
 }}}

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/59795#comment:11>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list