From c13df115bdbf48c4753d8406ee20ad0e28c4b957 Mon Sep 17 00:00:00 2001 From: deepench Date: Mon, 28 Sep 2026 09:47:05 +0100 Subject: [PATCH] Fix unbounded get_users() in theme-switch review-notice cleanup review_notice_data_remove() called get_users() with no arguments - loading every user on the site as a full WP_User object, then doing a get_user_meta() round-trip per user - purely to delete two user-meta keys that either exist or don't. Since the code never branched on the meta's actual value (only whether it existed), there was no need to read it first at all. Replaced the whole get_users()-plus-loop with two delete_metadata() calls (delete_all = true), which delete a meta key across every user in one query each, without ever loading a single user object. Verified live via the real wp-admin theme-switch UI (this class only loads inside is_admin(), so WP-CLI's own theme-switch bootstrap doesn't exercise it): set the two meta keys on multiple users, switched away from Flash, confirmed both keys were gone for every user afterward. --- inc/admin/class-flash-theme-review-notice.php | 21 +++++-------------- 1 file changed, 5 insertions(+), 16 deletions(-) diff --git a/inc/admin/class-flash-theme-review-notice.php b/inc/admin/class-flash-theme-review-notice.php index d856a74..e8d0221 100644 --- a/inc/admin/class-flash-theme-review-notice.php +++ b/inc/admin/class-flash-theme-review-notice.php @@ -182,7 +182,6 @@ public function ignore_theme_review_notice_partially() { * Remove the data set after the theme has been switched to other theme. */ public function review_notice_data_remove() { - $get_all_users = get_users(); $theme_installed_time = get_option( 'flash_theme_installed_time' ); // Delete options data. @@ -190,21 +189,11 @@ public function review_notice_data_remove() { delete_option( 'flash_theme_installed_time' ); } - // Delete user meta data for theme review notice. - foreach ( $get_all_users as $user ) { - $ignored_notice = get_user_meta( $user->ID, 'flash_ignore_theme_review_notice', true ); - $ignored_notice_partially = get_user_meta( $user->ID, 'nag_flash_ignore_theme_review_notice_partially', true ); - - // Delete permanent notice remove data. - if ( $ignored_notice ) { - delete_user_meta( $user->ID, 'flash_ignore_theme_review_notice' ); - } - - // Delete partial notice remove data. - if ( $ignored_notice_partially ) { - delete_user_meta( $user->ID, 'nag_flash_ignore_theme_review_notice_partially' ); - } - } + // Delete user meta data for theme review notice, for every user in + // one query per key - avoids loading every user on the site just to + // unconditionally delete a key that either exists or doesn't. + delete_metadata( 'user', 0, 'flash_ignore_theme_review_notice', '', true ); + delete_metadata( 'user', 0, 'nag_flash_ignore_theme_review_notice_partially', '', true ); } }