| @@ -17,12 +17,13 @@ | ||
| 17 | 17 | * Check if show "Settings General" page OR "System Info" |
| 18 | 18 | * |
| 19 | 19 | * @return bool |
| 20 | 20 | */ |
| 21 | -function wpbc_is_show_general_setting_options(){ //FixIn: 8.9.4.11 | |
| 21 | +function wpbc_is_show_general_setting_options(){ // FixIn: 8.9.4.11. | |
| 22 | 22 | |
| 23 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing | |
| 23 | 24 | if ( ( isset( $_GET['system_info'] ) ) && ( $_GET['system_info'] == 'show' ) ) { |
| 24 | - $nonce_gen_time = check_admin_referer( 'wpbc_settings_url_nonce' ); //FixIn: 9.2.2.1 | |
| 25 | + $nonce_gen_time = check_admin_referer( 'wpbc_settings_url_nonce' ); // FixIn: 9.2.2.1. | |
| 25 | 26 | return false; |
| 26 | 27 | } |
| 27 | 28 | return true; |
| 28 | 29 | } |
| @@ -75,15 +76,18 @@ | ||
| 75 | 76 | |
| 76 | 77 | if ( ! current_user_can( 'activate_plugins' ) ) { |
| 77 | 78 | return; |
| 78 | 79 | } |
| 80 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing | |
| 81 | + if ( ( isset( $_GET['reset'] ) ) && ( 'custom_forms' == $_GET['reset'] ) ) { // FixIn: 8.1.3.21. | |
| 79 | 82 | |
| 80 | - if ( ( isset( $_GET['reset'] ) ) && ( 'custom_forms' == $_GET['reset'] ) ) { //FixIn: 8.1.3.21 | |
| 81 | - | |
| 82 | 83 | wpbc_open_meta_box_section( 'wpbc_general_settings_system_info', 'System Info' ); |
| 83 | 84 | |
| 84 | - // Reset Custom Booking Forms to NONE | |
| 85 | - update_bk_option( 'booking_forms_extended', serialize( array() ) ); | |
| 85 | + global $wpdb; | |
| 86 | + if ( function_exists( 'wpbc_is_table_exists' ) && wpbc_is_table_exists( 'booking_form_structures' ) ) { | |
| 87 | + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.InterpolatedNotPrepared | |
| 88 | + $wpdb->query( "DELETE FROM {$wpdb->prefix}booking_form_structures WHERE form_slug <> 'standard'" ); | |
| 89 | + } | |
| 86 | 90 | |
| 87 | 91 | wpbc_show_message_in_settings( '<strong>Custom forms</strong> has been reseted!', 'info' ); |
| 88 | 92 | |
| 89 | 93 | wpbc_close_meta_box_section(); |
| @@ -99,20 +103,25 @@ | ||
| 99 | 103 | * |
| 100 | 104 | */ |
| 101 | 105 | function wpbc_settings__system_info__generate_php_from_pot() { |
| 102 | 106 | |
| 107 | + return; | |
| 108 | + | |
| 103 | 109 | if ( ! current_user_can( 'activate_plugins' ) ) { |
| 104 | 110 | return; |
| 105 | 111 | } |
| 106 | 112 | |
| 107 | - if ( ! empty( $_GET['pot'] ) ) { //FixIn: 8.1.3.21 | |
| 113 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing | |
| 114 | + if ( ! empty( $_GET['pot'] ) ) { // FixIn: 8.1.3.21. | |
| 108 | 115 | |
| 109 | 116 | wpbc_open_meta_box_section( 'wpbc_general_settings_system_info', 'System Info' ); |
| 110 | 117 | |
| 118 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing | |
| 111 | 119 | if ( '1' == $_GET['pot'] ) { |
| 112 | 120 | wpbc_pot_to_php(); |
| 113 | 121 | } |
| 114 | 122 | |
| 123 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing | |
| 115 | 124 | if ( 'erase__wpbc_all_translations' == $_GET['pot'] ) { |
| 116 | 125 | wpbc_delete_translation_php_files(); |
| 117 | 126 | } |
| 118 | 127 | |
| @@ -132,9 +141,10 @@ | ||
| 132 | 141 | if ( ! current_user_can( 'activate_plugins' ) ) { |
| 133 | 142 | return; |
| 134 | 143 | } |
| 135 | 144 | |
| 136 | - if ( ( isset( $_GET['update_translations'] ) ) && ( '1' == $_GET['update_translations'] ) ) { //FixIn: 8.1.3.21 | |
| 145 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing | |
| 146 | + if ( ( isset( $_GET['update_translations'] ) ) && ( '1' == $_GET['update_translations'] ) ) { // FixIn: 8.1.3.21. | |
| 137 | 147 | |
| 138 | 148 | wpbc_open_meta_box_section( 'wpbc_general_settings_system_info', 'System Info' ); |
| 139 | 149 | |
| 140 | 150 | wpbc_update_translations__from_wp(); |
| @@ -155,18 +165,21 @@ | ||
| 155 | 165 | if ( ! current_user_can( 'activate_plugins' ) ) { |
| 156 | 166 | return; |
| 157 | 167 | } |
| 158 | 168 | |
| 159 | - if ( isset( $_GET['show_translation_status'] ) ) { //FixIn: 8.1.3.21 | |
| 169 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing | |
| 170 | + if ( isset( $_GET['show_translation_status'] ) ) { // FixIn: 8.1.3.21. | |
| 160 | 171 | |
| 161 | 172 | wpbc_open_meta_box_section( 'wpbc_general_settings_system_info', 'System Info' ); |
| 162 | - | |
| 173 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing | |
| 163 | 174 | if ( '1' == $_GET['show_translation_status'] ){ |
| 164 | 175 | wpbc_show_translation_status_compare_wpbc_wp(); |
| 165 | 176 | } |
| 177 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing | |
| 166 | 178 | if ( '2' == $_GET['show_translation_status'] ){ |
| 167 | 179 | wpbc_show_translation_status_from_wp(); |
| 168 | 180 | } |
| 181 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing | |
| 169 | 182 | if ( '3' == $_GET['show_translation_status'] ){ |
| 170 | 183 | wpbc_show_translation_status_from_wpbc(); |
| 171 | 184 | } |
| 172 | 185 | |
| @@ -181,8 +194,9 @@ | ||
| 181 | 194 | * Link: http://server.com/wp-admin/admin.php?page=wpbc-settings&system_info=show&_wpnonce='. wp_create_nonce( 'wpbc_settings_url_nonce' ) .' #wpbc_general_settings_system_info_metabox |
| 182 | 195 | */ |
| 183 | 196 | function wpbc_settings__system_info__show_system_info(){ |
| 184 | 197 | |
| 198 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing | |
| 185 | 199 | if ( ( isset( $_GET['booking_system_info'] ) ) && ( $_GET['booking_system_info'] == 'show' ) ) { ?> |
| 186 | 200 | |
| 187 | 201 | <?php wpbc_open_meta_box_section( 'wpbc_general_settings_system_info', 'System Info' ); ?> |
| 188 | 202 | |
| @@ -200,17 +214,19 @@ | ||
| 200 | 214 | * |
| 201 | 215 | */ |
| 202 | 216 | function wpbc_settings__system_info__restore_dismissed_windows(){ |
| 203 | 217 | |
| 204 | - if ( ( isset( $_GET['restore_dismissed'] ) ) && ( $_GET['restore_dismissed'] == 'On' ) ) { //FixIn: 8.1.3.10 | |
| 218 | + // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing | |
| 219 | + if ( ( isset( $_GET['restore_dismissed'] ) ) && ( $_GET['restore_dismissed'] == 'On' ) ) { // FixIn: 8.1.3.10. | |
| 205 | 220 | |
| 206 | 221 | update_bk_option( 'booking_is_show_powered_by_notice', 'On' ); |
| 207 | - | |
| 208 | 222 | update_bk_option( 'booking_wpdev_copyright_adminpanel', 'On' ); |
| 223 | + update_bk_option( 'booking_menu_go_pro', 'show' ); | |
| 209 | 224 | |
| 210 | 225 | global $wpdb; |
| 211 | - // Delete all users booking windows states | |
| 212 | - if ( false === $wpdb->query( "DELETE FROM {$wpdb->usermeta} WHERE meta_key LIKE '%booking_win_%'" ) ) { // All users data | |
| 226 | + | |
| 227 | + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter | |
| 228 | + if ( false === $wpdb->query( "DELETE FROM {$wpdb->usermeta} WHERE meta_key LIKE '%booking_win_%'" ) ) { // Delete all users booking windows states. | |
| 213 | 229 | debuge_error( 'Error during deleting user meta at DB', __FILE__, __LINE__ ); |
| 214 | 230 | die(); |
| 215 | 231 | } else { |
| 216 | 232 | |
| @@ -217,11 +233,9 @@ | ||
| 217 | 233 | wpbc_open_meta_box_section( 'wpbc_general_settings_restore_dismissed', 'Info' ); |
| 218 | 234 | |
| 219 | 235 | ?><h2>All dismissed windows has been restored.</h2><?php |
| 220 | 236 | |
| 221 | - echo '<div class="clear"></div><hr/><center><a class="button button" href="' . wpbc_get_settings_url() . '">' | |
| 222 | - . 'Reload Page' | |
| 223 | - . '</a></center>'; | |
| 237 | + echo '<div class="clear"></div><hr/><center><a class="button button" href="' . esc_url( wpbc_get_settings_url() ) . '">Reload Page</a></center>'; | |
| 224 | 238 | |
| 225 | 239 | wpbc_close_meta_box_section(); |
| 226 | 240 | } |
| 227 | 241 | } |
| @@ -234,23 +248,21 @@ | ||
| 234 | 248 | * |
| 235 | 249 | */ |
| 236 | 250 | function wpbc_system_info() { |
| 237 | 251 | |
| 252 | + if ( current_user_can( 'activate_plugins' ) ) { // Only for Administrator or Super admin. More here: https://codex.wordpress.org/Roles_and_Capabilities . | |
| 238 | 253 | |
| 239 | - | |
| 240 | - if ( current_user_can( 'activate_plugins' ) ) { // Only for Administrator or Super admin. More here: https://codex.wordpress.org/Roles_and_Capabilities | |
| 241 | - | |
| 242 | - | |
| 243 | 254 | global $wpdb, $wp_version; |
| 244 | 255 | |
| 245 | - $all_plugins = get_plugins(); | |
| 256 | + $all_plugins = get_plugins(); | |
| 246 | 257 | $active_plugins = get_option( 'active_plugins' ); |
| 258 | + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter | |
| 259 | + $mysql_info = $wpdb->get_results( "SHOW VARIABLES LIKE 'sql_mode'" ); | |
| 247 | 260 | |
| 248 | - $mysql_info = $wpdb->get_results( "SHOW VARIABLES LIKE 'sql_mode'" ); | |
| 249 | 261 | if ( is_array( $mysql_info ) ) $sql_mode = $mysql_info[0]->Value; |
| 250 | 262 | if ( empty( $sql_mode ) ) $sql_mode = 'Not set'; |
| 251 | 263 | |
| 252 | - //FixIn: 8.4.7.24 | |
| 264 | + // FixIn: 8.4.7.24. | |
| 253 | 265 | $allow_url_fopen = ( ini_get( 'allow_url_fopen' ) ) ? 'On' : 'Off'; |
| 254 | 266 | $upload_max_filesize = ( ini_get( 'upload_max_filesize' ) ) ? ini_get( 'upload_max_filesize' ) : 'N/A'; |
| 255 | 267 | $post_max_size = ( ini_get( 'post_max_size' ) ) ? ini_get( 'post_max_size' ) : 'N/A'; |
| 256 | 268 | $max_execution_time = ( ini_get( 'max_execution_time' ) ) ? ini_get( 'max_execution_time' ) : 'N/A'; |
| @@ -258,9 +270,9 @@ | ||
| 258 | 270 | $memory_usage = ( function_exists( 'memory_get_usage' ) ) ? round( memory_get_usage() / 1024 / 1024, 2 ) . ' Mb' : 'N/A'; |
| 259 | 271 | $exif_read_data = ( is_callable( 'exif_read_data' ) ) ? 'Yes' . " ( V" . substr( phpversion( 'exif' ), 0, 4 ) . ")" : 'No'; |
| 260 | 272 | $iptcparse = ( is_callable( 'iptcparse' ) ) ? 'Yes' : 'No'; |
| 261 | 273 | $xml_parser_create = ( is_callable( 'xml_parser_create' ) ) ? 'Yes' : 'No'; |
| 262 | - $theme = ( function_exists( 'wp_get_theme' ) ) ? wp_get_theme() : get_theme( get_current_theme() ); | |
| 274 | + $theme = wp_get_theme(); | |
| 263 | 275 | |
| 264 | 276 | if ( function_exists( 'is_multisite' ) ) { |
| 265 | 277 | if ( is_multisite() ) $multisite = 'Yes'; |
| 266 | 278 | else $multisite = 'No'; |
| @@ -269,19 +281,22 @@ | ||
| 269 | 281 | |
| 270 | 282 | $system_info = array( |
| 271 | 283 | 'system_info' => '', |
| 272 | 284 | 'php_info' => '', |
| 273 | - 'active_plugins' => array(), //FixIn: 8.4.4.1 | |
| 274 | - 'inactive_plugins' => array() //FixIn: 8.4.4.1 | |
| 285 | + 'active_plugins' => array(), // FixIn: 8.4.4.1. | |
| 286 | + 'inactive_plugins' => array() // FixIn: 8.4.4.1. | |
| 275 | 287 | ); |
| 276 | 288 | |
| 277 | 289 | $ver_small_name = wpbc_get_plugin_version_type(); |
| 278 | 290 | if ( class_exists( 'wpdev_bk_multiuser' ) ) $ver_small_name = 'multiuser'; |
| 279 | 291 | |
| 292 | + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter | |
| 293 | + $mysql_version = $wpdb->get_var( 'SELECT VERSION() AS version' ); | |
| 294 | + | |
| 280 | 295 | $system_info['system_info'] = array( |
| 281 | 296 | 'Plugin Update' => ( defined( 'WPDEV_BK_VERSION' ) ) ? WPDEV_BK_VERSION : 'N/A', |
| 282 | 297 | 'Plugin Version' => ucwords( $ver_small_name ), |
| 283 | - 'Plugin Update Date' => date( "Y-m-d", filemtime( WPBC_FILE ) ), | |
| 298 | + 'Plugin Update Date' => gmdate( "Y-m-d", filemtime( WPBC_FILE ) ), | |
| 284 | 299 | |
| 285 | 300 | 'Server Default Timezone' => date_default_timezone_get(), |
| 286 | 301 | 'WordPress Timezone' => wp_timezone()->getName(), |
| 287 | 302 | |
| @@ -288,17 +303,17 @@ | ||
| 288 | 303 | 'WP Version' => $wp_version, |
| 289 | 304 | 'WP DEBUG' => ( ( defined('WP_DEBUG') ) && ( WP_DEBUG ) ) ? 'On' : 'Off', |
| 290 | 305 | 'WP DB Version' => get_option( 'db_version' ), |
| 291 | 306 | 'Operating System' => PHP_OS, |
| 292 | - 'Server' => $_SERVER["SERVER_SOFTWARE"], | |
| 307 | + 'Server' => isset( $_SERVER["SERVER_SOFTWARE"] ) ? sanitize_text_field( wp_unslash( $_SERVER["SERVER_SOFTWARE"] ) ) : 'N/A', | |
| 293 | 308 | 'PHP Version' => PHP_VERSION, |
| 294 | - 'MYSQL Version' => $wpdb->get_var( "SELECT VERSION() AS version" ), | |
| 309 | + 'MYSQL Version' => $mysql_version, | |
| 295 | 310 | 'SQL Mode' => $sql_mode, |
| 296 | 311 | 'Memory usage' => $memory_usage, |
| 297 | 312 | 'Site URL' => get_option( 'siteurl' ), |
| 298 | 313 | 'Home URL' => home_url(), |
| 299 | - 'SERVER[HTTP_HOST]' => $_SERVER['HTTP_HOST'], | |
| 300 | - 'SERVER[SERVER_NAME]' => $_SERVER['SERVER_NAME'], | |
| 314 | + 'SERVER[HTTP_HOST]' => isset( $_SERVER["HTTP_HOST"] ) ? sanitize_text_field( wp_unslash( $_SERVER["HTTP_HOST"] ) ) : 'N/A', | |
| 315 | + 'SERVER[SERVER_NAME]' => isset( $_SERVER["SERVER_NAME"] ) ? sanitize_text_field( wp_unslash( $_SERVER["SERVER_NAME"] ) ) : 'N/A', | |
| 301 | 316 | 'Multisite' => $multisite, |
| 302 | 317 | 'Active Theme' => $theme['Name'] . ' ' . $theme['Version'] |
| 303 | 318 | ); |
| 304 | 319 | |
| @@ -349,9 +364,9 @@ | ||
| 349 | 364 | $gd_info = gd_info(); |
| 350 | 365 | if ( isset( $gd_info['GD Version'] ) ) |
| 351 | 366 | $gd_info = $gd_info['GD Version']; |
| 352 | 367 | else |
| 353 | - $gd_info = json_encode( $gd_info ); | |
| 368 | + $gd_info = wp_json_encode( $gd_info ); | |
| 354 | 369 | } else { |
| 355 | 370 | $gd_info = 'Off'; |
| 356 | 371 | } |
| 357 | 372 | $system_info['php_info']['PHP GD'] = $gd_info; |
| @@ -359,12 +374,14 @@ | ||
| 359 | 374 | // More here https://docs.woocommerce.com/document/problems-with-large-amounts-of-data-not-saving-variations-rates-etc/ |
| 360 | 375 | |
| 361 | 376 | |
| 362 | 377 | foreach ( $all_plugins as $path => $plugin ) { |
| 363 | - if ( is_plugin_active( $path ) ) { | |
| 378 | + if ( ( ! empty( $plugin['Name'] ) ) && ( ! empty( $plugin['Version'] ) ) ) { | |
| 379 | + if ( is_plugin_active( $path ) ) { | |
| 364 | 380 | $system_info['active_plugins'][ $plugin['Name'] ] = $plugin['Version']; |
| 365 | - } else { | |
| 381 | + } else { | |
| 366 | 382 | $system_info['inactive_plugins'][ $plugin['Name'] ] = $plugin['Version']; |
| 383 | + } | |
| 367 | 384 | } |
| 368 | 385 | } |
| 369 | 386 | |
| 370 | 387 | // Showing |
| @@ -371,9 +388,9 @@ | ||
| 371 | 388 | foreach ( $system_info as $section_name => $section_values ) { |
| 372 | 389 | ?> |
| 373 | 390 | <span class="wpdevelop"> |
| 374 | 391 | <table class="table table-striped table-bordered"> |
| 375 | - <thead><tr><th colspan="2" style="border-bottom: 1px solid #eeeeee;padding: 10px;"><?php echo strtoupper( $section_name ); ?></th></tr></thead> | |
| 392 | + <thead><tr><th colspan="2" style="border-bottom: 1px solid #eeeeee;padding: 10px;"><?php echo esc_html( strtoupper( $section_name ) ); ?></th></tr></thead> | |
| 376 | 393 | <tbody> |
| 377 | 394 | <?php |
| 378 | 395 | if ( !empty( $section_values ) ) { |
| 379 | 396 | foreach ( $section_values as $key => $value ) { |
| @@ -378,10 +395,10 @@ | ||
| 378 | 395 | if ( !empty( $section_values ) ) { |
| 379 | 396 | foreach ( $section_values as $key => $value ) { |
| 380 | 397 | ?> |
| 381 | 398 | <tr> |
| 382 | - <td scope="row" style="width:18em;padding:4px 8px;"><?php echo $key; ?></td> | |
| 383 | - <td scope="row" style="padding:4px 8px;"><?php echo $value; ?></td> | |
| 399 | + <td scope="row" style="width:18em;padding:4px 8px;"><?php echo esc_html( $key ); ?></td> | |
| 400 | + <td scope="row" style="padding:4px 8px;"><?php echo esc_html( $value ); ?></td> | |
| 384 | 401 | </tr> |
| 385 | 402 | <?php |
| 386 | 403 | } |
| 387 | 404 | } |