Skip to content

Fix: Query hardened for the several model class - #3055

Open
Anindra123 wants to merge 1 commit into
security/modelsfrom
models/fixes
Open

Anindra123 wants to merge 1 commit into
security/modelsfrom
models/fixes

Conversation

@Anindra123

Copy link
Copy Markdown
Collaborator
  • CourseModel.php

    • Added abspath check
    • In get_courses added check for excludes id array and post status parameter and used prepare in clause
    • Utilized cap manage_options instead of administrator
  • models/EnrollmentModel.php

    • Added abspath check
    • In get_enrolled_data added check for status and course id post type
  • models/OrderModel.php

    • Added abspath check
    • In create_order after catch no rollback query was running
    • In get_refunds_by_user the $user_id was placed with direct interpolation with no prepare query check

@Anindra123 Anindra123 self-assigned this Oct 2, 2026
@Anindra123 Anindra123 added the 4.1.1 . label Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant