Skip to content

Commit 09ed3f9

Browse files
Merge pull request #1313 from Codeinwp/bugfix/pro/587
Restricted database query action to admins
2 parents 6528919 + f681d3c commit 09ed3f9

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

classes/Visualizer/Module/AIBuilder.php

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -365,6 +365,9 @@ public function uploadData(): void {
365365

366366
// ── Database query ────────────────────────────────────────────────
367367
case 'db_query':
368+
if ( ! current_user_can( 'manage_options' ) && ! is_super_admin() ) {
369+
wp_send_json_error( array( 'message' => __( 'Action not allowed for this user.', 'visualizer' ) ), 403 );
370+
}
368371
if ( empty( $_POST['db_query'] ) ) {
369372
wp_send_json_error( array( 'message' => __( 'No query provided.', 'visualizer' ) ) );
370373
}

0 commit comments

Comments
 (0)