Compare commits
9 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 7126fb291d | |||
|
71ffa2a1db
|
|||
| d271532f31 | |||
|
2390db2f0d
|
|||
|
3fc6a7048d
|
|||
|
15be511b4c
|
|||
| 332ab0b97d | |||
|
3b598e82dd
|
|||
|
8e81f3f81c
|
@@ -1,8 +1,8 @@
|
||||
export PHP_UPLOADS_CONF_VERSION=v4
|
||||
export ENTRYPOINT_CONF_VERSION=v7
|
||||
export ENTRYPOINT_CONF_VERSION=v8
|
||||
export ENTRYPOINT_MAILRELAY_CONF_VERSION=v2
|
||||
export MSMTP_CONF_VERSION=v4
|
||||
export HTACCESS_CONF_VERSION=v3
|
||||
export HTACCESS_CONF_VERSION=v4
|
||||
export USERS_CONF_VERSION=v1
|
||||
|
||||
wp() {
|
||||
@@ -42,11 +42,11 @@ core_install(){
|
||||
}
|
||||
|
||||
enable_auto_updates(){
|
||||
wp plugin deactivate disable-update-notifications --allow-root
|
||||
wp plugin uninstall disable-update-notifications --allow-root
|
||||
wp option delete disable_notification_setting --allow-root
|
||||
wp plugin auto-updates enable --all --allow-root
|
||||
wp theme auto-updates enable --all --allow-root
|
||||
wp "plugin deactivate disable-update-notifications --allow-root"
|
||||
wp "plugin uninstall disable-update-notifications --allow-root"
|
||||
wp "option delete disable_notification_setting --allow-root"
|
||||
wp "plugin auto-updates enable --all --allow-root"
|
||||
wp "theme auto-updates enable --all --allow-root"
|
||||
}
|
||||
|
||||
disable_auto_updates(){
|
||||
|
||||
+1
-1
@@ -62,7 +62,7 @@ services:
|
||||
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectregex.replacement=https://${DOMAIN}/$${2}"
|
||||
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectregex.permanent=true"
|
||||
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
|
||||
- "coop-cloud.${STACK_NAME}.version=2.19.1+6.9.4"
|
||||
- "coop-cloud.${STACK_NAME}.version=2.19.4+6.9.4"
|
||||
|
||||
db:
|
||||
image: "mariadb:12.2"
|
||||
|
||||
@@ -42,6 +42,19 @@ define('FORCE_SSL_ADMIN', true );
|
||||
define('COOKIE_DOMAIN', \$_SERVER['HTTP_HOST']);"
|
||||
{{ end }}
|
||||
|
||||
|
||||
UPLOADS_HTACCESS=/var/www/html/wp-content/uploads/.htaccess
|
||||
if [ ! -f "$UPLOADS_HTACCESS" ]; then
|
||||
mkdir -p /var/www/html/wp-content/uploads
|
||||
cat > "$UPLOADS_HTACCESS" <<'EOF'
|
||||
# Prevent PHP execution in uploads directory
|
||||
<FilesMatch "\.(?i:php|phtml|phar)$">
|
||||
Require all denied
|
||||
</FilesMatch>
|
||||
EOF
|
||||
chown www-data:www-data "$UPLOADS_HTACCESS"
|
||||
fi
|
||||
|
||||
if [ -n "$@" ]; then
|
||||
"$@"
|
||||
fi
|
||||
|
||||
+13
-7
@@ -3,12 +3,18 @@
|
||||
Require all denied
|
||||
</FilesMatch>
|
||||
|
||||
# Prevent PHP execution in uploads directory
|
||||
<Directory /var/www/html/wp-content/uploads>
|
||||
<FilesMatch "\.(?i:php|phtml|phar)$">
|
||||
Require all denied
|
||||
</FilesMatch>
|
||||
</Directory>
|
||||
# Block XML-RPC
|
||||
<Files xmlrpc.php>
|
||||
Require all denied
|
||||
</Files>
|
||||
|
||||
# Block wp2shell CVE-2026-63030
|
||||
<IfModule mod_rewrite.c>
|
||||
RewriteEngine On
|
||||
RewriteCond %{QUERY_STRING} rest_route=.*/batch/v1 [NC]
|
||||
RewriteRule .* - [F,L]
|
||||
RewriteRule ^wp-json/batch/v1 - [F,L]
|
||||
</IfModule>
|
||||
|
||||
{{ if eq (env "MULTISITE") "" -}}
|
||||
# BEGIN WordPress
|
||||
@@ -66,4 +72,4 @@ RewriteRule ^(.*\.php)$ $1 [L]
|
||||
RewriteRule . index.php [L]
|
||||
|
||||
# END WordPress Multisite
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
@@ -0,0 +1 @@
|
||||
patch to block XML-RPC via htaccess
|
||||
@@ -0,0 +1 @@
|
||||
temporarily block rest api against wp2shell CVE
|
||||
Reference in New Issue
Block a user