You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Have you checked to ensure there aren't other open Pull Requests for the same update/change?
Changes proposed in this Pull Request:
Three security issues reported against 4.2.14:
Profiler CSS selectors were concatenated into a :not() rule with strip_tags, allowing unauthenticated stored CSS injection. Any client selector carrying CSS metacharacters now voids that device's hide rule, as the browser already did, so nothing is injected and behaviour is unchanged.
The file-replace path skipped SVG sanitization; it now runs the same sanitizer as normal uploads before writing the file.
The dashboard widget exposed the full service_data (CDN key/secret) to any logged-in user; it is now gated on manage_options and only the stats fields are sent to the page.
Clearing only this device's selectors does not keep the surviving rule device-specific. The rendering logic below treats an empty mobile/desktop selector list as absent data and returns the other device's selectors without a media query, so an unsafe mobile submission with valid desktop data makes the desktop hide rule apply on mobile (and vice versa), potentially hiding an above-fold background. Preserve the tainted-device state through rendering and media-scope the remaining device; add an asymmetric-device regression case.
The reason will be displayed to describe this comment to others. Learn more.
🔵 Needs a closer look
QA check: The code checks pass and the prior finding is fixed. Confirm the dashboard widget and background lazy loading on a real site.
Validation details
Files reviewed: 1/7 changed files. Only tests/test-bg-selector.php changed after dc13197.
PHP 8.3 with the WordPress 7.1.2 test library: the three PR test classes pass at HEAD with 33 tests and 1 root-only skip.
With pr-base source and PR tests, all five test_personalized_css* tests fail on their assertions.
Runs code-review-agent_6ab4ed214db4a7.48343246 and code-review-agent_6ab503cc1942f4.69205567 checked the other six files. Their results were reused and not rerun.
QA steps
Log in as an administrator on a connected site with at least ten visits. Open Dashboard. Expect the Optimole widget to show visits, the visit limit, compression and traffic.
Log in as a subscriber and open Dashboard. Expect no Optimole widget.
Enable viewport lazy loading and background lazy loading in Optimole > Settings. Open a page with a background image above the fold on a phone and on a desktop. Expect the background to appear without delay on both.
Scroll to a background image below the fold on both devices. Expect it to load when it enters the screen.
Untested areas
The widget was not rendered because the repository has no built assets and JS dependencies are absent.
Background lazy loading was not checked in a browser.
Jest and Playwright suites were not run.
🤖 Automated review · run code-review-agent_6ab5092b391357.13357155.
girishpanchal30
changed the title
Fixed harden profiler, replace, widget
Fixed harden profiler, media replace, dashboard widget
Sep 24, 2026
girishpanchal30
changed the title
Fixed harden profiler, media replace, dashboard widget
Fixed Harden profiler, media replacement, and dashboard widget vulnerabilities
Sep 24, 2026
pirate-bot
added
the
released
Indicate that an issue has been resolved and released in a particular version of the product.
label
Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
releasedIndicate that an issue has been resolved and released in a particular version of the product.
6 participants
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
All Submissions:
Changes proposed in this Pull Request:
Three security issues reported against 4.2.14:
:not()rule withstrip_tags, allowing unauthenticated stored CSS injection. Any client selector carrying CSS metacharacters now voids that device's hide rule, as the browser already did, so nothing is injected and behaviour is unchanged.service_data(CDN key/secret) to any logged-in user; it is now gated onmanage_optionsand only the stats fields are sent to the page.Closes https://github.com/Codeinwp/optimole-service/issues/1805
Other information: