Skip to content

Release 4.4.2 — security hardening of admin notice dismissal (udx/lib-wp-bootstrap 1.3.5) - #842

Merged
andypotanin merged 2 commits into
latestfrom
fix/patchstack-ec72be3a
Sep 2, 2026
Merged

andypotanin merged 2 commits into
latestfrom
fix/patchstack-ec72be3a

Conversation

@andypotanin

@andypotanin andypotanin commented Sep 2, 2026 •

Copy link
Copy Markdown
Member

Summary

Security release. Updates the vendored udx/lib-wp-bootstrap package to 1.3.5, which hardens the ud_bootstrap_dismiss_notice AJAX handler (registered as wp_ajax_ud_bootstrap_dismiss_notice):

  • requires a valid nonce (check_ajax_referer)
  • requires the manage_options capability
  • restricts writable option keys to the dismiss_*_notice pattern (the only shape the library reads back)
  • sanitizes the stored values

Reported via Patchstack responsible disclosure (report ec72be3a, scheduled to publish Oct 1, 2026). Changelog wording intentionally avoids exploit detail until publication. Sibling handlers already carry nonce checks (CVE-2024-1385 fix in lib 1.3.3); this handler was missed.

Also included, driven by the Grype security scan failing on the PR:

  • lib/Google dependency updates (CVE-flagged): guzzlehttp/guzzle 7.10.0 → 7.15.5, phpseclib/phpseclib 3.0.48 → 3.0.57, google/protobuf 4.33.2 → 4.33.6 (+ transitive guzzlehttp/promises, guzzlehttp/psr7, symfony contracts/polyfills)
  • Vendored tree hygiene: lib/Google vendor is now installed with --no-dev (phpunit/php_codesniffer/composer-composer etc. no longer shipped), google/apiclient-services pruned to the Storage service via the package's own cleanup script (as before), and vendored .github/ directories removed — these were the sources of the remaining Grype hits (github-action CVEs in vendored workflow files, nested lockfiles of dev packages)
  • Root vendor autoloader regenerated with --no-dev, so the committed autoloader never references uncommitted dev files

Changes

Verification

On a live environment (wpcloud.io develop-stateless pod) running exactly this branch's tree (fresh-synced after pruning):

  • Plugin loads and reports 4.4.2 (autoloader sanity after dev-prune)
  • subscriber + exploit payload, no nonce → -1, target option untouched (previously success:1 with the option overwritten)
  • subscriber + valid nonce → "You are not allowed to do this action."
  • admin + valid nonce + out-of-pattern key → "Invalid key"
  • admin + valid nonce + legit dismiss_*_notice key → success:1 (dismiss flow preserved)
  • Verified at handler level, over HTTP in-pod, and end-to-end through the public CloudFront URL; on both an existing install (production DB clone) and a fresh WordPress install
  • Media offload to GCS with CDN URL rewriting exercised with the bumped google/guzzle/phpseclib libraries (upload → object in bucket → public 200)
  • Ghost Inspector regression suite — test 03 replays the exploit in a real browser as a subscriber and asserts -1

Copilot AI balanced review requested due to automatic review settings September 2, 2026 03:54

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Devin Review

Comment thread vendor/composer/autoload_static.php Outdated
Comment on lines +10 to +17
'0e6d7bf4a5811bfa5cf40c5ccd6fae6a' => __DIR__ . '/..' . '/symfony/polyfill-mbstring/bootstrap.php',
'6e3fae29631ef280660b3cdad06f25a8' => __DIR__ . '/..' . '/symfony/deprecation-contracts/function.php',
'a4a119a56e50fbb293281d9a48007e0e' => __DIR__ . '/..' . '/symfony/polyfill-php80/bootstrap.php',
'320cde22f66dd4f5d3fd621d3e88b98f' => __DIR__ . '/..' . '/symfony/polyfill-ctype/bootstrap.php',
'8825ede83f2f289127722d4e842cf7e8' => __DIR__ . '/..' . '/symfony/polyfill-intl-grapheme/bootstrap.php',
'e69f7f6ee287b969198c3c9d6777bd38' => __DIR__ . '/..' . '/symfony/polyfill-intl-normalizer/bootstrap.php',
'0d59ee240a4cd96ddbb4ff164fccea4d' => __DIR__ . '/..' . '/symfony/polyfill-php73/bootstrap.php',
'b6b991a57620e2fb6b2f66f03fe9ddc2' => __DIR__ . '/..' . '/symfony/string/Resources/functions.php',

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 Missing dependencies crash plugin startup

Loading vendor/autoload.php follows $files into uncommitted Symfony paths. The first require fails, so every WP-Stateless startup aborts.

Prompt for agents
Regenerate the committed Composer runtime files from a clean installation that matches the distributed vendor tree. The current vendor/composer/autoload_static.php, autoload_files.php, autoload_psr4.php, autoload_classmap.php, installed.php, and installed.json include require-dev packages, while vendor/symfony, vendor/league, vendor/psr, vendor/coenjacobs, and vendor/deliciousbrains are absent. Ensure vendor/autoload.php loads successfully from the release archive and retain the intended vendor/wpmetabox installation path.
Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The generated autoloader eagerly requires absent dev-dependency files, causing plugin loading to fail.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Updates WP-Stateless to 4.4.2 with hardened admin-notice dismissal handling.

Changes:

  • Adds nonce, capability, key-pattern, and sanitization checks.
  • Bumps release metadata and changelogs.
  • Updates Composer metadata and generated autoload files.
File summaries
File Description
wp-stateless-media.php Bumps plugin version.
vendor/udx/lib-wp-bootstrap/lib/classes/class-bootstrap.php Hardens the AJAX handler.
vendor/udx/lib-wp-bootstrap/changes.md Documents library release.
vendor/composer/installed.php Updates installed-package metadata.
vendor/composer/installed.json Updates package metadata.
vendor/composer/autoload_static.php Adds generated dev-package mappings.
vendor/composer/autoload_real.php Eagerly loads generated file mappings.
vendor/composer/autoload_psr4.php Adds PSR-4 mappings.
vendor/composer/autoload_files.php Adds generated file autoloads.
vendor/composer/autoload_classmap.php Adds generated class mappings.
readme.txt Updates stable tag and changelog.
composer.lock Locks lib-wp-bootstrap 1.3.5.
changes.md Adds the 4.4.2 release entry.
changelog.txt Adds the 4.4.2 release entry.
Review details
  • Files reviewed: 4/14 changed files
  • Comments generated: 0
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI review requested due to automatic review settings September 2, 2026 04:02

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The release ships thousands of unnecessary development files, and its broad dependency refresh is not fully reflected in the PR scope.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review details
  • Files reviewed: 2/4925 changed files
  • Comments generated: 1
  • Review effort level: Balanced

Comment thread changes.md
Comment on lines +3 to +5
* ENHANCEMENT - updated `guzzlehttp/guzzle` library from 7.10.0 to 7.15.5.
* ENHANCEMENT - updated `phpseclib/phpseclib` library from 3.0.48 to 3.0.57.
* ENHANCEMENT - updated `google/protobuf` library from 4.33.2 to 4.33.6.
@andypotanin
andypotanin force-pushed the fix/patchstack-ec72be3a branch from ec4ec35 to d5d35e1 Compare September 2, 2026 04:22
Copilot AI review requested due to automatic review settings September 2, 2026 04:22

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The bundled Google SDK rejects PHP 8.1 and ships protobuf 5.36.1 despite the plugin metadata and changelogs stating otherwise.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review details
  • Files reviewed: 2/661 changed files
  • Comments generated: 3
  • Review effort level: Balanced

Comment thread changelog.txt
* FIX - `udx/lib-wp-bootstrap` package updated to 1.3.5: security hardening of the admin notice dismissal AJAX handler (nonce verification, capability check, and option key restriction).
* ENHANCEMENT - updated `guzzlehttp/guzzle` library from 7.10.0 to 7.15.5.
* ENHANCEMENT - updated `phpseclib/phpseclib` library from 3.0.48 to 3.0.57.
* ENHANCEMENT - updated `google/protobuf` library from 4.33.2 to 4.33.6.
Comment thread changes.md
* FIX - `udx/lib-wp-bootstrap` package updated to 1.3.5: security hardening of the admin notice dismissal AJAX handler (nonce verification, capability check, and option key restriction).
* ENHANCEMENT - updated `guzzlehttp/guzzle` library from 7.10.0 to 7.15.5.
* ENHANCEMENT - updated `phpseclib/phpseclib` library from 3.0.48 to 3.0.57.
* ENHANCEMENT - updated `google/protobuf` library from 4.33.2 to 4.33.6.
Comment thread readme.txt
* FIX - `udx/lib-wp-bootstrap` package updated to 1.3.5: security hardening of the admin notice dismissal AJAX handler (nonce verification, capability check, and option key restriction).
* ENHANCEMENT - updated `guzzlehttp/guzzle` library from 7.10.0 to 7.15.5.
* ENHANCEMENT - updated `phpseclib/phpseclib` library from 3.0.48 to 3.0.57.
* ENHANCEMENT - updated `google/protobuf` library from 4.33.2 to 4.33.6.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The vendored SDK breaks advertised PHP 8.1 support and resolves protobuf v5 despite documenting v4.33.6.

Review details
  • Files reviewed: 2/661 changed files
  • Comments generated: 0 new
  • Review effort level: Balanced

Copilot AI review requested due to automatic review settings September 2, 2026 04:31
@andypotanin
andypotanin force-pushed the fix/patchstack-ec72be3a branch from d5d35e1 to 34b9efb Compare September 2, 2026 04:31

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The vendored Google autoloader now requires PHP 8.2 while the plugin still declares PHP 8.1 support.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review details
  • Files reviewed: 3/571 changed files
  • Comments generated: 0 new
  • Review effort level: Balanced

Copilot AI review requested due to automatic review settings September 2, 2026 04:36
@andypotanin
andypotanin force-pushed the fix/patchstack-ec72be3a branch from 34b9efb to fe0de8c Compare September 2, 2026 04:36
…7, protobuf 4.33.6) and prune dev files from vendored tree
@andypotanin
andypotanin force-pushed the fix/patchstack-ec72be3a branch from fe0de8c to c746443 Compare September 2, 2026 04:37

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The updated Google SDK dependency set requires PHP 8.2 while the plugin still advertises PHP 8.1 support.

Review details
  • Files reviewed: 3/547 changed files
  • Comments generated: 0 new
  • Review effort level: Balanced

Copilot AI review requested due to automatic review settings September 2, 2026 04:40

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The security fix is sound, but the 547-file dependency refresh includes extensive cryptographic, HTTP, and generated-code changes requiring final human validation.

Review details
  • Files reviewed: 3/547 changed files
  • Comments generated: 0 new
  • Review effort level: Balanced

@andypotanin

Copy link
Copy Markdown
Member Author

Bot feedback addressed and re-verified on the final tree:

  • Devin (autoloader eagerly requiring absent dev files): resolved by regenerating the root autoloader with --no-dev — autoload_files.php is no longer committed and the plugin boots cleanly from exactly this tree (verified on a live pod: loads, reports 4.4.2, media offload works).
  • Copilot (protobuf 5.x / brick/math 0.14+ pulling the platform requirement to PHP 8.2): resolved with conflict guards in lib/Google/composer.json (google/protobuf >=5.0, brick/math >=0.13); resolved set is protobuf 4.33.6 + brick/math 0.12.3, and lib/Google/vendor/composer/platform_check.php now gates at PHP 8.1.0 as advertised.
  • Grype findings cleared by the dependency updates plus dev-file/.github pruning — scan is green.

GI regression suite 3/3 passing against this branch on the dev environment, incl. the in-browser subscriber exploit test returning -1.

@andypotanin
andypotanin merged commit c2e8059 into latest Sep 2, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants