VDB
KO
HIGH 8.6

GHSA-3pwp-g2mj-5p3v

WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability

Quick fix

GHSA-3pwp-g2mj-5p3v — wp-coding-standards/wpcs: upgrade to the fixed version with the command below.

composer require wp-coding-standards/wpcs:^3.4.1

Details

### Impact

WordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the `WordPress.WP.EnqueuedResourceParameters` sniff. As a result, running PHPCS with WordPressCS over untrusted PHP code, for example, in a CI pipeline that lints pull requests, or on a developer machine reviewing third-party code, could lead to arbitrary command execution on the scanning host.

This affects users of the `WordPress` and `WordPress-Extra` rulesets. The `WordPress-Core` ruleset and the `WordPress-Docs` ruleset are not affected.

The vulnerability happens when the sniff checks whether the `$var` argument passed to functions such as `wp_enqueue_script()` or `wp_register_script()` evaluates to a falsy value. The sniff's `is_falsy()` method reconstructed the argument and ran it through `eval()`. Because of this, a maliciously crafted `$ver` argument such as `'system'('id')` would be executed during the scan.

### Patches

This issue has been fixed in WordPressCS 3.4.1. We recommend all users upgrade to 3.4.1 or later.

### Workaround

Users of the `WordPress` and `WordPress-Extra` rulesets, who cannot upgrade immediately, can disable the affected sniff by adding an `<exclude>` tag to their custom ruleset (the `<rule>` `ref` value might vary depending on the ruleset):

```xml <rule ref="WordPress"> <exclude name="WordPress.WP.EnqueuedResourceParameters"/> </rule> ```

To verify that the sniff has been disabled, run PHPCS with the `-e` flag, which lists all the sniffs a standard will run. `WordPress.WP.EnqueuedResourceParameters` should no longer appear in the output under the `WordPress` section:

``` phpcs -e --standard=/path/to/ruleset.xml ```

### Credits

Many thanks to [@FORIMOC](https://github.com/FORIMOC) for responsibly disclosing this vulnerability.

### How can I report a security bug?

Please report security vulnerabilities privately via [the "Security and quality" tab on the WPCS repository](https://github.com/WordPress/WordPress-Coding-Standards/security).

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist / wp-coding-standards/wpcs
Introduced in: 0.14.1 Fixed in: 3.4.1
Fix composer require wp-coding-standards/wpcs:^3.4.1

References