/home/techb158/public_html/wp-content/plugins/kirki/app/Supports
NameSizeModeActions
Facades/-0755rm
Form/-0755rm
ActionHooks.php4050644editdlrm
Canvas.php5810644editdlrm
CollectionItem.php42120644editdlrm
ContentManager.php24480644editdlrm
DateTime.php5560644editdlrm
EditorPreview.php9920644editdlrm
FileHandler.php43950644editdlrm
FilterHooks.php8140644editdlrm
PageUrl.php59900644editdlrm
Recaptcha.php26980644editdlrm
Role.php14710644editdlrm
Session.php29690644editdlrm
Template.php122870644editdlrm
Edit: /home/techb158/public_html/wp-content/plugins/kirki/app/Supports/FileHandler.php (4395B)
with_options([ 'redirection' => 0 ]) ->with_user_agent('WordPress') ->get($remote_file_url); if ($response->failed()) { return false; } // Save the file locally. // Local path to save the downloaded file. $local_file_path = clean_path(get_upload_directory() . '/' . $file_name, false); static::verify_directory_traversal($local_file_path); $is_downloaded = FileHelper::put($local_file_path, $response->body()); if (!$is_downloaded) { return false; } return $local_file_path; } /** * Same-site URLs are always allowed (e.g. dev config points the apps base * URL at content_url() on the site's own — sometimes private/loopback — * host). Any other host must resolve to a public address, so a remote zip * URL can't be used to probe the server's own internal network. * * @param string $url * @return bool */ private static function is_remote_host_allowed(string $url) { $host = wp_parse_url($url, PHP_URL_HOST); if (!is_string($host) || $host === '') { return false; } $site_host = wp_parse_url(home_url(), PHP_URL_HOST); if (is_string($site_host) && strcasecmp($host, $site_host) === 0) { return true; } return HelperFunctions::is_safe_url($url); } /** * @return array|false * return false on failure */ public static function extract_zip_file(string $zip_file_path, string $destination_dir) { if (!class_exists('PclZip')) { require_once ABSPATH . 'wp-admin/includes/class-pclzip.php'; } $zip_file_path = clean_path($zip_file_path, false); if (FileHelper::missing($zip_file_path)) { return false; } if (!FileHelper::is_directory($destination_dir)) { FileHelper::make_dir($destination_dir); } $zip = new PclZip($zip_file_path); static::validate_zip_file($zip); $result = $zip->extract( PCLZIP_OPT_PATH, $destination_dir ); if (is_array($result)) { return $result; } return false; } public static function validate_zip_file(PclZip $zip) { $list = $zip->listContent(); if (!is_array($list)) { throw new Exception(esc_html__('Failed to read ZIP file.', 'kirki')); } foreach ($list as $entry) { if (!isset($entry['filename'])) { throw new Exception(esc_html__('Invalid ZIP file.', 'kirki')); } static::validate_zip_entry($entry['filename']); } } private static function validate_zip_entry(string $entry_filename) { $entry_filename = clean_path($entry_filename, false); if ( $entry_filename === '' || str_contains($entry_filename, "\0") || str_starts_with($entry_filename, '/') || preg_match('/^[A-Za-z]:\//', $entry_filename) ) { throw new Exception(esc_html__('Invalid ZIP file.', 'kirki')); } return static::verify_directory_traversal($entry_filename); } Public static function verify_directory_traversal(string $path) { if (preg_match('#(^|/)\.\.(/|$)#', clean_path($path, false))) { /* translators: %s: File Path */ throw new Exception(sprintf(esc_html__('Directory traversal detected in %s.', 'kirki'), $path)); } return true; } }