| @@ -8,12 +8,12 @@ | ||
| 8 | 8 | add_action('wp_ajax_nopriv_lgfr_password_reset', [$this, 'reset_password_callback']); |
| 9 | 9 | } |
| 10 | 10 | |
| 11 | 11 | function onSubmit(){ |
| 12 | - $nonce = sanitize_text_field($_POST['nonce']); | |
| 13 | - $username = sanitize_text_field($_POST['user_login']); | |
| 14 | - $password = sanitize_text_field($_POST['user_password']); | |
| 15 | - $remember = sanitize_text_field($_POST['remember']) === 'true'; | |
| 12 | + $nonce = sanitize_text_field( wp_unslash( $_POST['nonce'] ?? '' ) ); | |
| 13 | + $username = sanitize_text_field( wp_unslash( $_POST['user_login'] ?? '' ) ); | |
| 14 | + $password = sanitize_text_field( wp_unslash( $_POST['user_password'] ?? '' ) ); | |
| 15 | + $remember = sanitize_text_field( wp_unslash( $_POST['remember'] ?? '' ) ) === 'true'; | |
| 16 | 16 | |
| 17 | 17 | if(!wp_verify_nonce($nonce, 'wp_ajax')){ |
| 18 | 18 | wp_send_json_error([ |
| 19 | 19 | 'message' => 'Invalid request', |
| @@ -39,10 +39,10 @@ | ||
| 39 | 39 | |
| 40 | 40 | function reset_password_callback(){ |
| 41 | 41 | global $wpdb, $current_site; |
| 42 | 42 | |
| 43 | - $nonce = sanitize_text_field($_POST['nonce']); | |
| 44 | - $user_email = sanitize_text_field($_POST['email']); | |
| 43 | + $nonce = sanitize_text_field( wp_unslash( $_POST['nonce'] ?? '' ) ); | |
| 44 | + $user_email = sanitize_email( wp_unslash( $_POST['email'] ?? '' ) ); | |
| 45 | 45 | $user = get_user_by('email', $user_email); |
| 46 | 46 | $user_login = isset($user->data->user_login) ? $user->data->user_login : false; |
| 47 | 47 | |
| 48 | 48 | |