|
|
|
|
|
by DanielLestrange
609 days ago
|
|
If anything, the problem here is call_user_func, which when an attacker HAS ACCESS TO THE CODE, can be dangerous. How on earth does emptying POST or REQUEST solve anything at all in regards?
How on earth does, no matter what crap ACF added BEFORE the takeover, this "Fix" justify a hostile takeover? If or not there is a security issue with this code (which there IS, but not with POST or REQUEST data) is not even the matter anymore - it was and is posed and defended as a "urgent action to fix a security issue in a plugin the author has no access to" And I repeat - there has not been any security fix!! Read my root comment:
> because the only relevant changes are actually neither introducing fixes, nor ever changing the plugin core code in a way that fixes security issues. And I stand by that. Anyone reading this code can see it. |
|
You can continue arguing with yourself, but I don't need to be there.