/* ===================| SSRF DEFENSE - ADDED SEP 28 2026 - START|====================== */ /* ===================| SSRF DEFENSE - ADDED SEP 28 2026 - START|====================== */ add_filter( 'http_request_args', 'restrict_outbound_requests', 10, 2 ); function restrict_outbound_requests( $args, $url ) { // Define your allowlist of trusted domains $allowed_domains = [ 'api.wordpress.org', // WordPress core updates 'downloads.wordpress.org', // Plugin/theme downloads 'accbusiness.com', // Your own domain ]; $parsed = wp_parse_url( $url ); $host = isset( $parsed['host'] ) ? strtolower( $parsed['host'] ) : ''; // Block private/internal IP ranges and metadata endpoint $blocked_patterns = [ '/^169\.254\./', // AWS metadata service (IMDSv1/v2) '/^10\./', // RFC1918 private '/^172\.(1[6-9]|2[0-9]|3[01])\./', // RFC1918 private '/^192\.168\./', // RFC1918 private '/^127\./', // Loopback '/^0\./', // Invalid '/^localhost$/i', // Localhost ]; foreach ( $blocked_patterns as $pattern ) { if ( preg_match( $pattern, $host ) ) { return new WP_Error( 'ssrf_blocked', 'Request to internal address blocked.' ); } } // Enforce allowlist $is_allowed = false; foreach ( $allowed_domains as $domain ) { if ( $host === strtolower( $domain ) || str_ends_with( $host, '.' . strtolower( $domain ) ) ) { $is_allowed = true; break; } } if ( ! $is_allowed ) { return new WP_Error( 'ssrf_blocked', "Outbound request to {$host} is not allowed." ); } return $args; } /* ===================| SSRF DEFENSE - ADDED SEP 28 2026 - END|====================== */ /* ===================| SSRF DEFENSE - ADDED SEP 28 2026 - END|====================== */
|