| @@ -8,8 +8,11 @@ | ||
| 8 | 8 | * @license GPL-2.0+ |
| 9 | 9 | * @link https://cmb2.io |
| 10 | 10 | */ |
| 11 | 11 | |
| 12 | +// Exit if accessed directly | |
| 13 | +if( !defined( 'ABSPATH' ) ) exit; | |
| 14 | + | |
| 12 | 15 | /** |
| 13 | 16 | * Helper function to provide directory path to CMB2 |
| 14 | 17 | * |
| 15 | 18 | * @since 2.0.0 |
| @@ -40,9 +43,9 @@ | ||
| 40 | 43 | if ( 'CMB2_REST' === $class_name || 0 === strpos( $class_name, 'CMB2_REST_' ) ) { |
| 41 | 44 | $path .= '/rest-api'; |
| 42 | 45 | } |
| 43 | 46 | |
| 44 | - include_once( cmb2_dir( "$path/{$class_name}.php" ) ); | |
| 47 | + include_once cmb2_dir( "$path/{$class_name}.php" ); | |
| 45 | 48 | } |
| 46 | 49 | |
| 47 | 50 | /** |
| 48 | 51 | * Get instance of the CMB2_Utils class |
| @@ -320,9 +323,9 @@ | ||
| 320 | 323 | if ( |
| 321 | 324 | $cmb->prop( 'save_fields' ) |
| 322 | 325 | // check nonce. |
| 323 | 326 | && isset( $_POST['submit-cmb'], $_POST['object_id'], $_POST[ $cmb->nonce() ] ) |
| 324 | - && wp_verify_nonce( sanitize_text_field( wp_unslash ( $_POST[ $cmb->nonce() ] ) ), $cmb->nonce() ) | |
| 327 | + && wp_verify_nonce( $_POST[ $cmb->nonce() ], $cmb->nonce() ) | |
| 325 | 328 | && $object_id && $_POST['object_id'] == $object_id |
| 326 | 329 | ) { |
| 327 | 330 | $cmb->save_fields( $object_id, $cmb->object_type(), $_POST ); |
| 328 | 331 | } |
| @@ -346,9 +349,8 @@ | ||
| 346 | 349 | |
| 347 | 350 | if ( isset( $format_parts[1] ) && $format_parts[1] ) { |
| 348 | 351 | printf( str_ireplace( '%4$s', '%1$s', $format_parts[1] ), esc_attr( $args['save_button'] ) ); |
| 349 | 352 | } |
| 350 | - | |
| 351 | 353 | } |
| 352 | 354 | |
| 353 | 355 | /** |
| 354 | 356 | * Display a metabox form (or optionally return it) & save it on submission. |