403Webshell
Server IP : 62.171.151.215  /  Your IP : 216.73.217.53
Web Server : nginx/1.18.0
System : Linux vmi3128365 5.15.0-176-generic #186-Ubuntu SMP Fri Mar 13 11:01:42 UTC 2026 x86_64
User : alex ( 1000)
PHP Version : 8.4.18
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/anti-tabac.com/wp-content/mu-plugins/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/anti-tabac.com/wp-content/mu-plugins/wp-security-hardening.php
<?php
/*
Plugin Name: WP Security Hardening
Description: Mitigates REST API batch route confusion (CVE-2026-63030) and author__not_in SQLi (CVE-2026-60137).
Version: 1.0.0
Author: WordPress Security
*/

add_filter('rest_pre_dispatch', function($result, $server, $request) {
    if ($result !== null) return $result;
    $route = $request->get_route();
    if (preg_match('#/v2/batch\b#i', $route) && !current_user_can('read')) {
        return new WP_Error(
            'rest_batch_forbidden',
            'Batch endpoint requires authentication.',
            array('status' => 403)
        );
    }
    return $result;
}, 5, 3);

add_action('pre_get_posts', function($query) {
    if (!empty($query->query_vars['author__not_in'])) {
        $query->query_vars['author__not_in'] = array_map('absint',
            (array) $query->query_vars['author__not_in']);
    }
});

Youez - 2016 - github.com/yon3zu
LinuXploit