← All changes
|
libraries/ct-ajax-list-table/includes/ajax-functions.php
+3
-3
5.8.6
→
6.0.4
View file →
| @@ -20,9 +20,9 @@ | ||
| 20 | 20 | wp_send_json_error(); |
| 21 | 21 | } |
| 22 | 22 | |
| 23 | 23 | // Setup the CT Table |
| 24 | - $ct_table = ct_setup_table( sanitize_text_field( $_GET['object'] ) ); | |
| 24 | + $ct_table = ct_setup_table( sanitize_text_field( wp_unslash( $_GET['object'] ) ) ); | |
| 25 | 25 | |
| 26 | 26 | if( ! is_object( $ct_table ) ) { |
| 27 | 27 | wp_send_json_error(); |
| 28 | 28 | } |
| @@ -42,10 +42,10 @@ | ||
| 42 | 42 | |
| 43 | 43 | // Setup this constant to allow from CT_List_Table meet that this render comes from this plugin |
| 44 | 44 | @define( 'IS_CT_AJAX_LIST_TABLE', true ); |
| 45 | 45 | |
| 46 | - if( is_array( $_GET['query_args'] ) ) { | |
| 47 | - $query_args = map_deep( $_GET['query_args'], 'sanitize_text_field' ); | |
| 46 | + if( isset( $_GET['query_args'] ) && is_array( $_GET['query_args'] ) ) { | |
| 47 | + $query_args = map_deep( wp_unslash( $_GET['query_args'] ), 'sanitize_text_field' ); | |
| 48 | 48 | } else { |
| 49 | 49 | $query_args = json_decode( wp_unslash( $_GET['query_args'] ), true ); |
| 50 | 50 | // Sanitize |
| 51 | 51 | $query_args = map_deep( $query_args, 'sanitize_text_field' ); |