| @@ -1,25 +1,35 @@ | ||
| 1 | 1 | <div |
| 2 | - <?php echo $wrapper_attr; ?>> | |
| 3 | - <div class="betterdocs-social-share-heading"> | |
| 4 | - <?php | |
| 5 | - if ( $title ) { | |
| 6 | - echo wp_sprintf( '<h5>%s</h5>', esc_html( $title ) ); | |
| 7 | - } | |
| 8 | - ?> | |
| 9 | - </div> | |
| 2 | + <?php | |
| 3 | +// phpcs:disable WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedVariableFound -- view template receives variables via extract(); prefixing is impractical. | |
| 4 | +if ( ! defined( 'ABSPATH' ) ) { | |
| 5 | + exit; | |
| 6 | +} | |
| 7 | +echo $wrapper_attr; //phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?>> | |
| 8 | + <div class="betterdocs-social-share-heading"> | |
| 9 | + <?php | |
| 10 | + if ( $title ) { | |
| 11 | + $title_tag = isset( $title_tag ) ? $title_tag : 'h4'; | |
| 12 | + // Allow-list the tag name — esc_attr() does not stop a space/= from | |
| 13 | + // injecting an attribute in this tag-name position (stored XSS via | |
| 14 | + // the shortcode title_tag). | |
| 15 | + $title_tag = betterdocs()->template_helper->is_valid_tag( $title_tag ); | |
| 16 | + echo wp_sprintf( '<%1$s class="betterdocs-social-share-title-tag">%2$s</%1$s>', esc_attr( $title_tag ), esc_html( $title ) ); | |
| 17 | + } | |
| 18 | + ?> | |
| 19 | + </div> | |
| 10 | 20 | |
| 11 | - <ul class="betterdocs-social-share-links"> | |
| 12 | - <?php | |
| 13 | - if ( ! empty( $links ) ) { | |
| 14 | - foreach ( $links as $key => $social ) { | |
| 15 | - echo wp_sprintf( | |
| 16 | - '<li><a href="%s" target="_blank"><img src="%s" alt="%s"></a></li>', | |
| 17 | - esc_url( $social['link'] ), | |
| 18 | - esc_html( $social['icon'] ), | |
| 19 | - esc_attr( $social['alt'] ) | |
| 20 | - ); | |
| 21 | - } | |
| 22 | - } | |
| 23 | - ?> | |
| 24 | - </ul> | |
| 21 | + <ul class="betterdocs-social-share-links"> | |
| 22 | + <?php | |
| 23 | + if ( ! empty( $links ) ) { | |
| 24 | + foreach ( $links as $key => $social ) { | |
| 25 | + echo wp_sprintf( | |
| 26 | + '<li><a href="%s" target="_blank"><img src="%s" alt="%s"></a></li>', | |
| 27 | + esc_url( $social['link'] ), | |
| 28 | + esc_html( $social['icon'] ), | |
| 29 | + esc_attr( $social['alt'] ) | |
| 30 | + ); | |
| 31 | + } | |
| 32 | + } | |
| 33 | + ?> | |
| 34 | + </ul> | |
| 25 | 35 | </div> |