| Server IP : 81.2.241.106 / Your IP : 216.73.216.165 Web Server : Apache/2.4.67 (Debian) System : Linux tranq-f.bakta.org 5.10.0-45-amd64 #1 SMP Debian 5.10.259-1 (2026-07-02) x86_64 User : lisky ( 1002) PHP Version : 7.4.33 Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare, MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : OFF | Sudo : ON | Pkexec : OFF Directory : /var/www/lisky/wp-content/themes/lisciweb/ |
Upload File : |
<?php
/**
* Plugin Name: WP2Shell Batch Guard (Must-Use)
* Description: Blocks anonymous REST batch API (wp2shell mitigation).
* Version: 1.1.0
*/
if (!defined('ABSPATH')) {
exit;
}
function wp2shell_fixer_is_batch_route($route) {
$route = strtolower((string) $route);
$route = function_exists('untrailingslashit') ? untrailingslashit($route) : rtrim($route, '/');
if ($route === '/batch/v1' || $route === 'batch/v1') {
return true;
}
return (bool) preg_match('#(^|/)batch/v1$#', $route);
}
function wp2shell_fixer_require_auth_for_rest_batch($result, $server, $request) {
if (!is_object($request) || !method_exists($request, 'get_route')) {
return $result;
}
if (!wp2shell_fixer_is_batch_route($request->get_route())) {
return $result;
}
if (function_exists('is_user_logged_in') && is_user_logged_in()) {
return $result;
}
return new WP_Error(
'rest_batch_authentication_required',
'Authentication is required to use the batch API.',
array('status' => 401)
);
}
add_filter('rest_pre_dispatch', 'wp2shell_fixer_require_auth_for_rest_batch', -1000, 3);
add_filter('rest_authentication_errors', function ($result) {
if (true === $result || is_wp_error($result)) {
return $result;
}
$uri = isset($_SERVER['REQUEST_URI']) ? (string) $_SERVER['REQUEST_URI'] : '';
$rest = isset($_REQUEST['rest_route']) ? (string) $_REQUEST['rest_route'] : '';
$hit = (stripos($uri, 'batch/v1') !== false)
|| (stripos($rest, 'batch/v1') !== false)
|| (stripos($uri, 'rest_route=/batch') !== false);
if (!$hit) {
return $result;
}
if (function_exists('is_user_logged_in') && is_user_logged_in()) {
return $result;
}
return new WP_Error(
'rest_batch_authentication_required',
'Authentication is required to use the batch API.',
array('status' => 401)
);
}, 99);