PluginProbe
Booking Calendar / 11.9
Booking Calendar v11.9
11.9 11.8.4 11.8.3 11.8.2 11.8.1 11.8 11.7 11.6.1 11.6 11.5 11.4.3 11.4.2 11.4.1 11.4 11.3 11.2.1 11.2 11.1 11.0 10.15.7 10.15.6 10.1.3 10.10 10.10.1 10.10.2 All 205 releases
← All changes | includes/_news/wpbc_news.php +6 -4 10.1.3 → 11.9 View file →
@@ -13,9 +13,9 @@
13 13 */
14 14
15 15 if ( ! defined( 'ABSPATH' ) ) exit; // Exit if accessed directly
16 16
17 -//FixIn: 9.6.1.8
17 +// FixIn: 9.6.1.8.
18 18
19 19 /**
20 20 * Show message in top header
21 21 *
@@ -44,9 +44,11 @@
44 44 position: relative;
45 45 z-index: 99;
46 46 }
47 47 </style><?php
48 - ?><div class="wpbc_message_wrapper <?php echo 'wpbc__version__' . $version ?>"><?php
48 + ?>
49 + <div class="wpbc_message_wrapper <?php
50 + echo 'wpbc__version__' . esc_attr( $version ); ?>"><?php
49 51
50 52 // Send Ajax request to get info about the notifications
51 53 wp_nonce_field('wpbc_ajax_message_top_nonce', "wpbc_ajax_message_top_nonce" , true , true );
52 54
@@ -57,9 +59,9 @@
57 59
58 60 console.log( '== Before Ajax Send - SHOW_MESSAGE_TOP ==' );
59 61
60 62 jQuery.ajax({
61 - url: '<?php echo admin_url( 'admin-ajax.php' ); ?>',
63 + url: '<?php echo esc_url( admin_url( 'admin-ajax.php' ) ); ?>',
62 64 type:'POST',
63 65 success: function (data, textStatus){
64 66
65 67 // console.log( 'AJAX _ SHOW_MESSAGE_TOP', data );
@@ -101,9 +103,9 @@
101 103 $action_name = 'wpbc_ajax_message_top_nonce';
102 104 $nonce_post_key = 'wpbc_nonce';
103 105 $result_check = check_ajax_referer( $action_name, $nonce_post_key );
104 106
105 - // $user_id = ( isset( $_REQUEST['wpbc_ajx_user_id'] ) ) ? intval( $_REQUEST['wpbc_ajx_user_id'] ) : wpbc_get_current_user_id();
107 + // $user_id = ( isset( $_REQUEST['wpbc_ajx_user_id'] ) ) ? intval( $_REQUEST['wpbc_ajx_user_id'] ) : wpbc_get_current_user_id(); // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.NonceVerification.Missing
106 108
107 109 // Check if there were some errors --------------------------------------------------------------------------------
108 110 $error_messages = $ajax_errors->get_error_messages();
109 111