Done !
| Server IP : 54.36.91.62 / Your IP : 216.73.216.38 Web Server : Apache System : Linux webm008.cluster127.gra.hosting.ovh.net 6.18.42-ovh-vps-grsec-zfs+ #1 SMP PREEMPT_DYNAMIC Wed Aug 5 15:59:48 CEST 2026 x86_64 User : awaywithxm ( 25098) PHP Version : 7.0.33 Disable Function : _dyuweyrj4,_dyuweyrj4r,dl MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : ON | Sudo : OFF | Pkexec : OFF Directory : /home/awaywithxm/www/wp-content/plugins/secupress/inc/functions/ |
Upload File : |
<?php
defined( 'ABSPATH' ) or die( 'Cheatin\' uh?' );
add_filter( 'wp_update_attachment_metadata', 'secupress_fix_wp_496_1' );
/**
* Fix the vulnerability discovered on thumb meta data on june 2018, not patched in WP core
*
* @param (array) $data Meta data from a media.
* @return (array) $data Meta data from a media.
* @author Julio Potier
* @since 1.4.5.1
* @source https://blog.ripstech.com/2018/wordpress-file-delete-to-code-execution/
**/
function secupress_fix_wp_496_1( $data ) {
if ( isset( $data['thumb'] ) ) {
$data['thumb'] = basename( $data['thumb'] );
}
return $data;
}