Skip to content

Multiple security issues resolved in QueryHelper - #3046

Open
harunollyo wants to merge 16 commits into
4.2.0from
harun
Open

harunollyo wants to merge 16 commits into
4.2.0from
harun

Conversation

@harunollyo

@harunollyo harunollyo commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Fixes multiple SQL injection vulnerabilities in QueryHelper by validating and quoting user-influenced identifiers (column names, table names, ORDER BY values) and preparing previously unprepared variables.

Changes

  • get_row / get_all: Sanitize the ORDER BY clause to block injection via unescaped order values.
  • update_where_in: Prepare variables that were previously interpolated directly into the query.
  • prepare_set_clause(): Escape and quote column names.
  • prepare_like_clause(): Validate array keys used as column names.
  • New quote_sql_identifier(): Helper that validates and backtick-quotes SQL identifiers. It is now used for where_col and table names across QueryHelper queries.
  • Refactored identifier validation and quoting, and fixed WPCS issues.

Testing

Unit tests added for the new behavior:
vendor/bin/phpunit --filter=QueryHelperTest

image

@harunollyo
harunollyo marked this pull request as draft October 1, 2026 06:15
@harunollyo
harunollyo marked this pull request as ready for review October 1, 2026 07:04
@harunollyo harunollyo self-assigned this Oct 1, 2026
@harunollyo
harunollyo requested a review from shewa12 October 1, 2026 07:04
@harunollyo harunollyo added the 4.1.1 . label Oct 1, 2026

@shewa12 shewa12 left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left a couple of inline comments on update_where_in() double-escaping and prepare_set_clause().

Comment thread helpers/QueryHelper.php
Comment thread helpers/QueryHelper.php
@harunollyo
harunollyo changed the base branch from 4.1.1 to 4.2.0 October 9, 2026 06:20
@harunollyo harunollyo added 4.2.0 and removed 4.1.1 . labels Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants