fix: remove exe from allowed file upload list #1781
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
related PR #1353
This PR removes executable files (.exe) from the list of allowed file types in the file upload field.
WordPress restricts file uploads by default to a whitelist of safe MIME types, such as common images (jpg, png), documents (pdf, doc), audio (mp3), and videos (mp4), blocking others for security reasons.
The "unfiltered_upload" capability allows bypassing these restrictions to upload any file type, but no user role, including
Administrator, has this capability by default. As theAdministratoris not getting the capability by default, we are also not allowing it from our end.Summary by CodeRabbit
✏️ Tip: You can customize this high-level summary in your review settings.