[Backport to release/11.0] Fix SQL injection via report_args.orderby on Analytics CSV export - #67551
Conversation
…7544) Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: Lourens Schep <lourensschep@gmail.com> Co-authored-by: Chi-Hsuan Huang <chihsuan.tw@gmail.com>
Test using WordPress PlaygroundThe changes in this pull request can be previewed and tested using a WordPress Playground instance. Test this pull request with WordPress Playground. Note that this URL is valid for 30 days from when this comment was last updated. You can update it by closing/reopening the PR or pushing a commit that changes plugin code. |
|
Hi @woocommercebot! Your PR contains REST API changes. Please consider updating the REST API documentation if your changes affect the public API. Changed API files: |
Testing GuidelinesHi @LiamSarsfield , Apart from reviewing the code changes, please make sure to review the testing instructions (Guide) and verify that relevant tests (E2E, Unit, Integration, etc.) have been added or updated as needed. Reminder: PR reviewers are required to document testing performed. This includes:
|
This PR is a cherry-pick of #67544 to
release/11.0.Original PR Description
See 461-gh-Automattic/woocommerce.