Skip to content

🔒 fix(views): audit and remediate security vulnerabilities in views - #3064

Open
b-l-i-n-d wants to merge 6 commits into
devfrom
fix/security-bllind
Open

b-l-i-n-d wants to merge 6 commits into
devfrom
fix/security-bllind

Conversation

@b-l-i-n-d

Copy link
Copy Markdown
Collaborator
  • Remediate direct script execution vulnerabilities across all view templates in views/elements/ and views/fragments/ by adding standard defined( 'ABSPATH' ) || exit; guards.
  • Fix direct $_GET/$_POST superglobal access by routing requests through TUTOR\Input sanitizer wrappers.
  • Secure unescaped dynamic outputs using appropriate escaping functions (esc_html, esc_attr, esc_url).
  • Add missing nonce verification fields and checks on forms and interactive modals.
  • Deprecate legacy views/elements/filters.php in favor of views/elements/list-filters.php and harden loose comparisons.

…ents

- Add ABSPATH exit guards across views/elements/ and views/fragments/
- Replace extract() with explicit variable assignment in fragments
- Enforce attribute escaping (esc_attr, esc_url) and wp_kses_post on pagination
- Add tutor_nonce_field() to bulk action forms
- Replace administrator role checks with manage_options capability
- Resolve WordPress global variable overrides
- Add defensive variable initialization for template views
- Add bin/security-audit automation harness and update phpcs ruleset
@b-l-i-n-d
b-l-i-n-d added this pull request to stack #3066 October 6, 2026 09:16
@b-l-i-n-d
b-l-i-n-d marked this pull request as ready for review October 8, 2026 04:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant