| 1 |
<div |
| 2 |
<?php |
| 3 |
// phpcs:disable WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound -- view template receives variables via extract(); prefixing is impractical. |
| 4 |
if ( ! defined( 'ABSPATH' ) ) { |
| 5 |
exit; |
| 6 |
} |
| 7 |
echo $wrapper_attr; //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>> |
| 8 |
<div class="betterdocs-social-share-heading"> |
| 9 |
<?php |
| 10 |
if ( $title ) { |
| 11 |
$title_tag = isset( $title_tag ) ? $title_tag : 'h4'; |
| 12 |
// Allow-list the tag name — esc_attr() does not stop a space/= from |
| 13 |
// injecting an attribute in this tag-name position (stored XSS via |
| 14 |
// the shortcode title_tag). |
| 15 |
$title_tag = betterdocs()->template_helper->is_valid_tag( $title_tag ); |
| 16 |
echo wp_sprintf( '<%1$s class="betterdocs-social-share-title-tag">%2$s</%1$s>', esc_attr( $title_tag ), esc_html( $title ) ); |
| 17 |
} |
| 18 |
?> |
| 19 |
</div> |
| 20 |
|
| 21 |
<ul class="betterdocs-social-share-links"> |
| 22 |
<?php |
| 23 |
if ( ! empty( $links ) ) { |
| 24 |
foreach ( $links as $key => $social ) { |
| 25 |
echo wp_sprintf( |
| 26 |
'<li><a href="%s" target="_blank"><img src="%s" alt="%s"></a></li>', |
| 27 |
esc_url( $social['link'] ), |
| 28 |
esc_html( $social['icon'] ), |
| 29 |
esc_attr( $social['alt'] ) |
| 30 |
); |
| 31 |
} |
| 32 |
} |
| 33 |
?> |
| 34 |
</ul> |
| 35 |
</div> |
| 36 |
|