PluginProbe
Booking Calendar / 11.9
Booking Calendar v11.9
11.9 11.8.4 11.8.3 11.8.2 11.8.1 11.8 11.7 11.6.1 11.6 11.5 11.4.3 11.4.2 11.4.1 11.4 11.3 11.2.1 11.2 11.1 11.0 10.15.7 10.15.6 10.1.3 10.10 10.10.1 10.10.2 All 205 releases
← All changes | core/admin/wpbc-settings-functions.php +55 -38 10.1.3 → 11.9 View file →
@@ -17,12 +17,13 @@
17 17 * Check if show "Settings General" page OR "System Info"
18 18 *
19 19 * @return bool
20 20 */
21 -function wpbc_is_show_general_setting_options(){ //FixIn: 8.9.4.11
21 +function wpbc_is_show_general_setting_options(){ // FixIn: 8.9.4.11.
22 22
23 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
23 24 if ( ( isset( $_GET['system_info'] ) ) && ( $_GET['system_info'] == 'show' ) ) {
24 - $nonce_gen_time = check_admin_referer( 'wpbc_settings_url_nonce' ); //FixIn: 9.2.2.1
25 + $nonce_gen_time = check_admin_referer( 'wpbc_settings_url_nonce' ); // FixIn: 9.2.2.1.
25 26 return false;
26 27 }
27 28 return true;
28 29 }
@@ -75,15 +76,18 @@
75 76
76 77 if ( ! current_user_can( 'activate_plugins' ) ) {
77 78 return;
78 79 }
80 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
81 + if ( ( isset( $_GET['reset'] ) ) && ( 'custom_forms' == $_GET['reset'] ) ) { // FixIn: 8.1.3.21.
79 82
80 - if ( ( isset( $_GET['reset'] ) ) && ( 'custom_forms' == $_GET['reset'] ) ) { //FixIn: 8.1.3.21
81 -
82 83 wpbc_open_meta_box_section( 'wpbc_general_settings_system_info', 'System Info' );
83 84
84 - // Reset Custom Booking Forms to NONE
85 - update_bk_option( 'booking_forms_extended', serialize( array() ) );
85 + global $wpdb;
86 + if ( function_exists( 'wpbc_is_table_exists' ) && wpbc_is_table_exists( 'booking_form_structures' ) ) {
87 + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.InterpolatedNotPrepared
88 + $wpdb->query( "DELETE FROM {$wpdb->prefix}booking_form_structures WHERE form_slug <> 'standard'" );
89 + }
86 90
87 91 wpbc_show_message_in_settings( '<strong>Custom forms</strong> has been reseted!', 'info' );
88 92
89 93 wpbc_close_meta_box_section();
@@ -99,20 +103,25 @@
99 103 *
100 104 */
101 105 function wpbc_settings__system_info__generate_php_from_pot() {
102 106
107 + return;
108 +
103 109 if ( ! current_user_can( 'activate_plugins' ) ) {
104 110 return;
105 111 }
106 112
107 - if ( ! empty( $_GET['pot'] ) ) { //FixIn: 8.1.3.21
113 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
114 + if ( ! empty( $_GET['pot'] ) ) { // FixIn: 8.1.3.21.
108 115
109 116 wpbc_open_meta_box_section( 'wpbc_general_settings_system_info', 'System Info' );
110 117
118 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
111 119 if ( '1' == $_GET['pot'] ) {
112 120 wpbc_pot_to_php();
113 121 }
114 122
123 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
115 124 if ( 'erase__wpbc_all_translations' == $_GET['pot'] ) {
116 125 wpbc_delete_translation_php_files();
117 126 }
118 127
@@ -132,9 +141,10 @@
132 141 if ( ! current_user_can( 'activate_plugins' ) ) {
133 142 return;
134 143 }
135 144
136 - if ( ( isset( $_GET['update_translations'] ) ) && ( '1' == $_GET['update_translations'] ) ) { //FixIn: 8.1.3.21
145 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
146 + if ( ( isset( $_GET['update_translations'] ) ) && ( '1' == $_GET['update_translations'] ) ) { // FixIn: 8.1.3.21.
137 147
138 148 wpbc_open_meta_box_section( 'wpbc_general_settings_system_info', 'System Info' );
139 149
140 150 wpbc_update_translations__from_wp();
@@ -155,18 +165,21 @@
155 165 if ( ! current_user_can( 'activate_plugins' ) ) {
156 166 return;
157 167 }
158 168
159 - if ( isset( $_GET['show_translation_status'] ) ) { //FixIn: 8.1.3.21
169 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
170 + if ( isset( $_GET['show_translation_status'] ) ) { // FixIn: 8.1.3.21.
160 171
161 172 wpbc_open_meta_box_section( 'wpbc_general_settings_system_info', 'System Info' );
162 -
173 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
163 174 if ( '1' == $_GET['show_translation_status'] ){
164 175 wpbc_show_translation_status_compare_wpbc_wp();
165 176 }
177 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
166 178 if ( '2' == $_GET['show_translation_status'] ){
167 179 wpbc_show_translation_status_from_wp();
168 180 }
181 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
169 182 if ( '3' == $_GET['show_translation_status'] ){
170 183 wpbc_show_translation_status_from_wpbc();
171 184 }
172 185
@@ -181,8 +194,9 @@
181 194 * Link: http://server.com/wp-admin/admin.php?page=wpbc-settings&system_info=show&_wpnonce='. wp_create_nonce( 'wpbc_settings_url_nonce' ) .' #wpbc_general_settings_system_info_metabox
182 195 */
183 196 function wpbc_settings__system_info__show_system_info(){
184 197
198 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
185 199 if ( ( isset( $_GET['booking_system_info'] ) ) && ( $_GET['booking_system_info'] == 'show' ) ) { ?>
186 200
187 201 <?php wpbc_open_meta_box_section( 'wpbc_general_settings_system_info', 'System Info' ); ?>
188 202
@@ -200,17 +214,19 @@
200 214 *
201 215 */
202 216 function wpbc_settings__system_info__restore_dismissed_windows(){
203 217
204 - if ( ( isset( $_GET['restore_dismissed'] ) ) && ( $_GET['restore_dismissed'] == 'On' ) ) { //FixIn: 8.1.3.10
218 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
219 + if ( ( isset( $_GET['restore_dismissed'] ) ) && ( $_GET['restore_dismissed'] == 'On' ) ) { // FixIn: 8.1.3.10.
205 220
206 221 update_bk_option( 'booking_is_show_powered_by_notice', 'On' );
207 -
208 222 update_bk_option( 'booking_wpdev_copyright_adminpanel', 'On' );
223 + update_bk_option( 'booking_menu_go_pro', 'show' );
209 224
210 225 global $wpdb;
211 - // Delete all users booking windows states
212 - if ( false === $wpdb->query( "DELETE FROM {$wpdb->usermeta} WHERE meta_key LIKE '%booking_win_%'" ) ) { // All users data
226 +
227 + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
228 + if ( false === $wpdb->query( "DELETE FROM {$wpdb->usermeta} WHERE meta_key LIKE '%booking_win_%'" ) ) { // Delete all users booking windows states.
213 229 debuge_error( 'Error during deleting user meta at DB', __FILE__, __LINE__ );
214 230 die();
215 231 } else {
216 232
@@ -217,11 +233,9 @@
217 233 wpbc_open_meta_box_section( 'wpbc_general_settings_restore_dismissed', 'Info' );
218 234
219 235 ?><h2>All dismissed windows has been restored.</h2><?php
220 236
221 - echo '<div class="clear"></div><hr/><center><a class="button button" href="' . wpbc_get_settings_url() . '">'
222 - . 'Reload Page'
223 - . '</a></center>';
237 + echo '<div class="clear"></div><hr/><center><a class="button button" href="' . esc_url( wpbc_get_settings_url() ) . '">Reload Page</a></center>';
224 238
225 239 wpbc_close_meta_box_section();
226 240 }
227 241 }
@@ -234,23 +248,21 @@
234 248 *
235 249 */
236 250 function wpbc_system_info() {
237 251
252 + if ( current_user_can( 'activate_plugins' ) ) { // Only for Administrator or Super admin. More here: https://codex.wordpress.org/Roles_and_Capabilities .
238 253
239 -
240 - if ( current_user_can( 'activate_plugins' ) ) { // Only for Administrator or Super admin. More here: https://codex.wordpress.org/Roles_and_Capabilities
241 -
242 -
243 254 global $wpdb, $wp_version;
244 255
245 - $all_plugins = get_plugins();
256 + $all_plugins = get_plugins();
246 257 $active_plugins = get_option( 'active_plugins' );
258 + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
259 + $mysql_info = $wpdb->get_results( "SHOW VARIABLES LIKE 'sql_mode'" );
247 260
248 - $mysql_info = $wpdb->get_results( "SHOW VARIABLES LIKE 'sql_mode'" );
249 261 if ( is_array( $mysql_info ) ) $sql_mode = $mysql_info[0]->Value;
250 262 if ( empty( $sql_mode ) ) $sql_mode = 'Not set';
251 263
252 - //FixIn: 8.4.7.24
264 + // FixIn: 8.4.7.24.
253 265 $allow_url_fopen = ( ini_get( 'allow_url_fopen' ) ) ? 'On' : 'Off';
254 266 $upload_max_filesize = ( ini_get( 'upload_max_filesize' ) ) ? ini_get( 'upload_max_filesize' ) : 'N/A';
255 267 $post_max_size = ( ini_get( 'post_max_size' ) ) ? ini_get( 'post_max_size' ) : 'N/A';
256 268 $max_execution_time = ( ini_get( 'max_execution_time' ) ) ? ini_get( 'max_execution_time' ) : 'N/A';
@@ -258,9 +270,9 @@
258 270 $memory_usage = ( function_exists( 'memory_get_usage' ) ) ? round( memory_get_usage() / 1024 / 1024, 2 ) . ' Mb' : 'N/A';
259 271 $exif_read_data = ( is_callable( 'exif_read_data' ) ) ? 'Yes' . " ( V" . substr( phpversion( 'exif' ), 0, 4 ) . ")" : 'No';
260 272 $iptcparse = ( is_callable( 'iptcparse' ) ) ? 'Yes' : 'No';
261 273 $xml_parser_create = ( is_callable( 'xml_parser_create' ) ) ? 'Yes' : 'No';
262 - $theme = ( function_exists( 'wp_get_theme' ) ) ? wp_get_theme() : get_theme( get_current_theme() );
274 + $theme = wp_get_theme();
263 275
264 276 if ( function_exists( 'is_multisite' ) ) {
265 277 if ( is_multisite() ) $multisite = 'Yes';
266 278 else $multisite = 'No';
@@ -269,19 +281,22 @@
269 281
270 282 $system_info = array(
271 283 'system_info' => '',
272 284 'php_info' => '',
273 - 'active_plugins' => array(), //FixIn: 8.4.4.1
274 - 'inactive_plugins' => array() //FixIn: 8.4.4.1
285 + 'active_plugins' => array(), // FixIn: 8.4.4.1.
286 + 'inactive_plugins' => array() // FixIn: 8.4.4.1.
275 287 );
276 288
277 289 $ver_small_name = wpbc_get_plugin_version_type();
278 290 if ( class_exists( 'wpdev_bk_multiuser' ) ) $ver_small_name = 'multiuser';
279 291
292 + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
293 + $mysql_version = $wpdb->get_var( 'SELECT VERSION() AS version' );
294 +
280 295 $system_info['system_info'] = array(
281 296 'Plugin Update' => ( defined( 'WPDEV_BK_VERSION' ) ) ? WPDEV_BK_VERSION : 'N/A',
282 297 'Plugin Version' => ucwords( $ver_small_name ),
283 - 'Plugin Update Date' => date( "Y-m-d", filemtime( WPBC_FILE ) ),
298 + 'Plugin Update Date' => gmdate( "Y-m-d", filemtime( WPBC_FILE ) ),
284 299
285 300 'Server Default Timezone' => date_default_timezone_get(),
286 301 'WordPress Timezone' => wp_timezone()->getName(),
287 302
@@ -288,17 +303,17 @@
288 303 'WP Version' => $wp_version,
289 304 'WP DEBUG' => ( ( defined('WP_DEBUG') ) && ( WP_DEBUG ) ) ? 'On' : 'Off',
290 305 'WP DB Version' => get_option( 'db_version' ),
291 306 'Operating System' => PHP_OS,
292 - 'Server' => $_SERVER["SERVER_SOFTWARE"],
307 + 'Server' => isset( $_SERVER["SERVER_SOFTWARE"] ) ? sanitize_text_field( wp_unslash( $_SERVER["SERVER_SOFTWARE"] ) ) : 'N/A',
293 308 'PHP Version' => PHP_VERSION,
294 - 'MYSQL Version' => $wpdb->get_var( "SELECT VERSION() AS version" ),
309 + 'MYSQL Version' => $mysql_version,
295 310 'SQL Mode' => $sql_mode,
296 311 'Memory usage' => $memory_usage,
297 312 'Site URL' => get_option( 'siteurl' ),
298 313 'Home URL' => home_url(),
299 - 'SERVER[HTTP_HOST]' => $_SERVER['HTTP_HOST'],
300 - 'SERVER[SERVER_NAME]' => $_SERVER['SERVER_NAME'],
314 + 'SERVER[HTTP_HOST]' => isset( $_SERVER["HTTP_HOST"] ) ? sanitize_text_field( wp_unslash( $_SERVER["HTTP_HOST"] ) ) : 'N/A',
315 + 'SERVER[SERVER_NAME]' => isset( $_SERVER["SERVER_NAME"] ) ? sanitize_text_field( wp_unslash( $_SERVER["SERVER_NAME"] ) ) : 'N/A',
301 316 'Multisite' => $multisite,
302 317 'Active Theme' => $theme['Name'] . ' ' . $theme['Version']
303 318 );
304 319
@@ -349,9 +364,9 @@
349 364 $gd_info = gd_info();
350 365 if ( isset( $gd_info['GD Version'] ) )
351 366 $gd_info = $gd_info['GD Version'];
352 367 else
353 - $gd_info = json_encode( $gd_info );
368 + $gd_info = wp_json_encode( $gd_info );
354 369 } else {
355 370 $gd_info = 'Off';
356 371 }
357 372 $system_info['php_info']['PHP GD'] = $gd_info;
@@ -359,12 +374,14 @@
359 374 // More here https://docs.woocommerce.com/document/problems-with-large-amounts-of-data-not-saving-variations-rates-etc/
360 375
361 376
362 377 foreach ( $all_plugins as $path => $plugin ) {
363 - if ( is_plugin_active( $path ) ) {
378 + if ( ( ! empty( $plugin['Name'] ) ) && ( ! empty( $plugin['Version'] ) ) ) {
379 + if ( is_plugin_active( $path ) ) {
364 380 $system_info['active_plugins'][ $plugin['Name'] ] = $plugin['Version'];
365 - } else {
381 + } else {
366 382 $system_info['inactive_plugins'][ $plugin['Name'] ] = $plugin['Version'];
383 + }
367 384 }
368 385 }
369 386
370 387 // Showing
@@ -371,9 +388,9 @@
371 388 foreach ( $system_info as $section_name => $section_values ) {
372 389 ?>
373 390 <span class="wpdevelop">
374 391 <table class="table table-striped table-bordered">
375 - <thead><tr><th colspan="2" style="border-bottom: 1px solid #eeeeee;padding: 10px;"><?php echo strtoupper( $section_name ); ?></th></tr></thead>
392 + <thead><tr><th colspan="2" style="border-bottom: 1px solid #eeeeee;padding: 10px;"><?php echo esc_html( strtoupper( $section_name ) ); ?></th></tr></thead>
376 393 <tbody>
377 394 <?php
378 395 if ( !empty( $section_values ) ) {
379 396 foreach ( $section_values as $key => $value ) {
@@ -378,10 +395,10 @@
378 395 if ( !empty( $section_values ) ) {
379 396 foreach ( $section_values as $key => $value ) {
380 397 ?>
381 398 <tr>
382 - <td scope="row" style="width:18em;padding:4px 8px;"><?php echo $key; ?></td>
383 - <td scope="row" style="padding:4px 8px;"><?php echo $value; ?></td>
399 + <td scope="row" style="width:18em;padding:4px 8px;"><?php echo esc_html( $key ); ?></td>
400 + <td scope="row" style="padding:4px 8px;"><?php echo esc_html( $value ); ?></td>
384 401 </tr>
385 402 <?php
386 403 }
387 404 }