PluginProbe
WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services / 5.2.0
WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services v5.2.0
8.7.8 8.7.7 8.7.6 8.7.5 8.7.4 8.7.3 8.7.2 8.7.1 8.7.0 8.6.9 8.6.8 8.6.7 8.6.6 8.6.5 8.6.4 8.6.2 8.6.1 8.6.0 8.5.9 8.5.8 8.5.7 8.5.6 8.5.5 8.5.4 8.5.3 All 534 releases
← All changes | functions.php +286 -401 8.7.55.2.0 View file →
@@ -3,48 +3,11 @@
3 3 * @param $type
4 4 * Display wpwBot Icon ball
5 5 */
6 6 if (!defined('ABSPATH')) exit; // Exit if accessed directly
7 -
8 -
9 -function qcld_custom_search_form( $form ) {
10 - // Add a hidden input to limit search to 'product' post type
11 - if (get_option('wp_chatbot_agent_image') == "custom-agent.png") {
12 - $wp_chatbot_custom_agent_path = get_option('wp_chatbot_custom_agent_path');
13 - } else if (get_option('wp_chatbot_agent_image') != "custom-agent.png") {
14 - $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_agent_image');
15 - } else {
16 - $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . 'custom-agent.png';
17 - }
18 - $hidden_field = '<a class="wp-chatbot qc_wpbot_chat_link" id="wp-chatbot-search-btn" data-search-type="product" data-search-term="" style="max-height: 50px; margin-left: 10px;padding: 0 !important;position: absolute;top: -9px;right: -60px;"><img src="'. esc_url($wp_chatbot_custom_agent_path) .'" alt=""></a>';
19 - $block_content = str_replace( '</form>', $hidden_field . '</form>', $form );
20 - return $block_content;
21 -}
22 -if(get_option('wpbot_enable_on_search') == 1 && (get_option('disable_floating_button') != '1') && get_option('disable_wp_chatbot') != 1 ){
23 - add_filter( 'get_search_form', 'qcld_custom_search_form' );
24 - add_filter( 'render_block_core/search', 'qcld_modify_gutenberg_search_block', 10, 2 );
25 -}
26 -
27 -
28 -function qcld_modify_gutenberg_search_block( $block_content, $block ) {
29 - // Add a hidden input to limit search to 'product' post type
30 - if (get_option('wp_chatbot_agent_image') == "custom-agent.png") {
31 - $wp_chatbot_custom_agent_path = get_option('wp_chatbot_custom_agent_path');
32 - } else if (get_option('wp_chatbot_agent_image') != "custom-agent.png") {
33 - $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_agent_image');
34 - } else {
35 - $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . 'custom-agent.png';
36 - }
37 - $hidden_field = '<button type="button" class="wp-chatbot qc_wpbot_chat_link" id="wp-chatbot-search-btn" data-search-type="product" data-search-term="" style="max-height: 50px; margin-left: 10px;padding: 0 !important"><img src="'. esc_url($wp_chatbot_custom_agent_path) .'" alt=""></button>';
38 - // Inject the hidden field before the closing </form> tag
39 - $block_content = str_replace( '</div></form>', $hidden_field . '</div></form>', $block_content );
40 - return $block_content;
41 -}
42 -if(get_option('disable_floating_button') != '1'){
43 - add_action('wp_footer', 'wp_chatbot_load_footer_html');
44 -}
45 -add_action( 'admin_footer', 'qcld_style_for_hide_iframe');
46 -function qcld_style_for_hide_iframe(){
7 +add_action('wp_footer', 'wp_chatbot_load_footer_html');
8 +add_action( 'admin_footer', 'qc_style_for_hide_iframe');
9 +function qc_style_for_hide_iframe(){
47 10 ?>
48 11 <script>
49 12 jQuery( document ).ready(function() {
50 13 setInterval(function(){
@@ -58,62 +21,8 @@
58 21 });
59 22 </script>
60 23 <?php
61 24 }
62 -/**
63 - * Extract a YouTube video ID from common URL formats.
64 - *
65 - * @param string $url YouTube watch, embed, short, or youtu.be URL.
66 - * @return string Video ID or empty string.
67 - */
68 -if ( ! function_exists( 'qcld_wpbot_extract_youtube_id' ) ) {
69 - function qcld_wpbot_extract_youtube_id( $url ) {
70 - $url = trim( (string) $url );
71 - if ( $url === '' ) {
72 - return '';
73 - }
74 -
75 - if ( preg_match( '/(?:youtube\.com\/(?:embed\/|shorts\/|live\/|watch\?(?:.*&)?v=)|youtu\.be\/)([A-Za-z0-9_-]{11})/', $url, $matches ) ) {
76 - return $matches[1];
77 - }
78 -
79 - $path = (string) wp_parse_url( $url, PHP_URL_PATH );
80 - $base = basename( $path );
81 - if ( preg_match( '/^[A-Za-z0-9_-]{11}$/', $base ) ) {
82 - return $base;
83 - }
84 -
85 - return '';
86 - }
87 -}
88 -if ( ! function_exists( 'qcld_wpbot_youtube_icon_embed_src' ) ) {
89 - function qcld_wpbot_youtube_icon_embed_src( $url ) {
90 - $video_id = qcld_wpbot_extract_youtube_id( $url );
91 - if ( $video_id === '' ) {
92 - return '';
93 - }
94 -
95 - return add_query_arg(
96 - array(
97 - 'autoplay' => '1',
98 - 'mute' => '1',
99 - 'loop' => '1',
100 - 'playlist' => $video_id,
101 - 'controls' => '0',
102 - 'showinfo' => '0',
103 - 'rel' => '0',
104 - 'fs' => '0',
105 - 'iv_load_policy' => '3',
106 - 'cc_load_policy' => '0',
107 - 'disablekb' => '1',
108 - 'playsinline' => '1',
109 - 'modestbranding' => '1',
110 - 'color' => 'white',
111 - ),
112 - 'https://www.youtube.com/embed/' . rawurlencode( $video_id )
113 - );
114 - }
115 -}
116 25 function wp_chatbot_load_footer_html(){
117 26 if ( get_option('disable_wp_chatbot') != 1 && wp_chatbot_load_controlling() === true) {
118 27
119 28 ?>
@@ -118,10 +27,9 @@
118 27
119 28 ?>
120 29 <style>
121 30 <?php if(get_option('wp_chatbot_custom_css')!="") {
122 -
123 - echo wp_strip_all_tags( get_option('wp_chatbot_custom_css') );// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
31 + echo sanitize_text_field(get_option('wp_chatbot_custom_css'));
124 32 }
125 33 ?>
126 34 </style>
127 35
@@ -133,27 +41,10 @@
133 41 }
134 42 ?>
135 43 <style>
136 44 .wp-chatbot-container {
137 - background-color: #eceef3 !important;
138 45 background-image: url(<?php echo esc_url($qcld_wb_chatbot_board_bg_path); ?>) !important;
139 - background-size: cover !important;
140 - background-position: center !important;
141 - background-repeat: no-repeat !important;
142 46 }
143 - .wp-chatbot-template-01 #wp-chatbot-board-container,
144 - .wp-chatbot-template-01 .wp-chatbot-board-container {
145 - background-color: #eceef3 !important;
146 - background-image: none !important;
147 - }
148 - .wp-chatbot-template-01 #wp-chatbot-board-container::before,
149 - .wp-chatbot-template-01 .wp-chatbot-board-container::before {
150 - background-color: #eceef3 !important;
151 - background-image: url(<?php echo esc_url($qcld_wb_chatbot_board_bg_path); ?>) !important;
152 - background-size: cover !important;
153 - background-position: center !important;
154 - background-repeat: no-repeat !important;
155 - }
156 47 </style>
157 48 <?php }
158 49 $wp_chatbot_enable_rtl = "";
159 50 if (get_option('enable_wp_chatbot_rtl') == '1') {
@@ -163,33 +54,33 @@
163 54 // if (get_option('enable_wp_chatbot_mobile_full_screen')==1) {
164 55 $wp_chatbot_enable_mobile_screen .= "wp-chatbot-mobile-full-screen";
165 56 // }
166 57 ?>
167 - <div id="wp-chatbot-chat-container" class="<?php echo esc_attr($wp_chatbot_enable_rtl .' '.$wp_chatbot_enable_mobile_screen); ?>" style="<?php if(get_option('disable_floating_button') == '1'){ echo 'display:none';} ?>">
58 + <div id="wp-chatbot-chat-container" class="<?php echo esc_attr($wp_chatbot_enable_rtl .' '.$wp_chatbot_enable_mobile_screen); ?>">
168 59 <div id="wp-chatbot-integration-container">
169 60 <div class="wp-chatbot-integration-button-container">
170 61 <?php if (get_option('enable_wp_chatbot_skype_floating_icon') == 1) { ?>
171 62 <a href="skype:<?php echo esc_attr(get_option('enable_wp_chatbot_skype_id')); ?>?chat"><span
172 - class="inetegration-skype-btn" title="<?php esc_attr_e('Skype', 'chatbot'); ?>"> </span></a>
63 + class="inetegration-skype-btn" title="<?php esc_attr_e('Skype', 'wpchatbot'); ?>"> </span></a>
173 64 <?php } ?>
174 65 <?php if (get_option('enable_wp_chatbot_floating_whats') == 1) { ?>
175 66 <a href="<?php echo esc_url('https://api.whatsapp.com/send?phone=' . get_option('qlcd_wp_chatbot_whats_num')); ?>"
176 67 target="_blank"><span class="intergration-whats"
177 - title="<?php esc_html_e('WhatsApp', 'chatbot'); ?>"></span></a>
68 + title="<?php esc_html_e('WhatsApp', 'wpchatbot'); ?>"></span></a>
178 69 <?php } ?>
179 70 <?php if (get_option('enable_wp_chatbot_floating_viber') == 1) { ?>
180 71 <a href="<?php echo esc_url('https://live.viber.com/#/' . get_option('qlcd_wp_chatbot_viber_acc')); ?>"
181 72 target="_blank"><span class="intergration-viber"
182 - title="<?php esc_html_e('Viber', 'chatbot'); ?>"></span></a>
73 + title="<?php esc_html_e('Viber', 'wpchatbot'); ?>"></span></a>
183 74 <?php } ?>
184 75 <?php if (get_option('enable_wp_chatbot_floating_phone') == 1 && get_option('qlcd_wp_chatbot_phone') != "") { ?>
185 76 <a href="tel:<?php echo esc_attr(get_option('qlcd_wp_chatbot_phone')); ?>"><span
186 77 class="intergration-phone"
187 - title="<?php esc_html_e('Phone', 'chatbot'); ?>"> </span></a>
78 + title="<?php esc_html_e('Phone', 'wpchatbot'); ?>"> </span></a>
188 79 <?php } ?>
189 80 <?php if (get_option('enable_wp_chatbot_floating_link') == 1 && get_option('qlcd_wp_chatbot_weblink') != "") { ?>
190 81 <a href="<?php echo esc_url(get_option('qlcd_wp_chatbot_weblink')); ?>" target="_blank"><span
191 - class="intergration-weblink" title="<?php esc_html_e('Web Link', 'chatbot'); ?>"></span></a>
82 + class="intergration-weblink" title="<?php esc_html_e('Web Link', 'wpchatbot'); ?>"></span></a>
192 83 <?php } ?>
193 84 </div>
194 85 </div>
195 86 <?php
@@ -202,9 +93,9 @@
202 93 }
203 94 if (file_exists(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/template.php')) {
204 95 require_once(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/template.php');
205 96 } else {
206 - echo "<h2>" . esc_html__('No wpWBot Theme Found!', 'chatbot') . "</h2>";
97 + echo "<h2>" . __('No wpWBot Theme Found!', 'wpchatbot') . "</h2>";
207 98 }
208 99 ?>
209 100 <?php
210 101 if (get_option('disable_wp_chatbot_notification') != 1) {
@@ -211,9 +102,9 @@
211 102 ?>
212 103 <div id="wp-chatbot-notification-container" class="wp-chatbot-notification-container">
213 104 <div class="wp-chatbot-notification-controller">
214 105 <span class="wp-chatbot-notification-close">
215 - <?php esc_html_e('X', 'chatbot'); ?>
106 + <?php esc_html_e('X', 'wpchatbot'); ?>
216 107 </span>
217 108 </div>
218 109 <?php
219 110 $testingTip="";
@@ -226,9 +117,9 @@
226 117 }
227 118 ?>
228 119 <div class="wp-chatbot-notification-agent-profile">
229 120 <div class="wp-chatbot-notification-widget-avatar" ><img
230 - src="<?php echo esc_url($wp_chatbot_custom_agent_path); ?>" alt=""></div>
121 + src="<?php echo esc_attr($wp_chatbot_custom_agent_path); ?>" alt=""></div>
231 122 <div class="wp-chatbot-notification-welcome"><?php echo wp_kses_post(wpb_randmom_message_handle(maybe_unserialize(get_option('qlcd_wp_chatbot_welcome')))) . ' <strong>' . esc_html(get_option('qlcd_wp_chatbot_host')) . '</strong>'; ?></div>
232 123 </div>
233 124 <?php
234 125 //update_option('qlcd_wp_chatbot_notifications','Welcome to WpBot');
@@ -251,72 +142,14 @@
251 142 $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_icon');
252 143 } else {
253 144 $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . 'custom.png';
254 145 }
255 - $_wpbot_icon_video = get_option('wp_chatbot_icon_video', '');
256 - $_wpbot_video_is_youtube = ( strpos( $_wpbot_icon_video, 'youtube.com' ) !== false || strpos( $_wpbot_icon_video, 'youtu.be' ) !== false );
257 - $_wpbot_youtube_embed_src = $_wpbot_video_is_youtube ? qcld_wpbot_youtube_icon_embed_src( $_wpbot_icon_video ) : '';
258 - $_wpbot_video_delay_ms = absint( get_option( 'wp_chatbot_icon_video_delay', 0 ) ) * 1000;
259 -
260 - $wp_chatbot_ball_is_youtube = ($_wpbot_icon_video !== '' && (strpos($_wpbot_icon_video, 'youtube.com') !== false || strpos($_wpbot_icon_video, 'youtu.be') !== false));
261 - $wp_chatbot_ball_is_video = ($_wpbot_icon_video !== '' && !$wp_chatbot_ball_is_youtube);
262 - $wp_chatbot_ball_has_video = ($wp_chatbot_ball_is_youtube || $wp_chatbot_ball_is_video);
263 146 ?>
264 147 <img src="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>"
265 - alt="wpChatIcon" qcld_agent="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>"
266 - id="wp-chatbot-ball-icon-img"
267 - <?php if ($wp_chatbot_ball_has_video) { echo 'style="display:none;"'; } ?> >
268 - <?php if ( $_wpbot_icon_video !== '' ) : ?>
269 - <?php if ( $_wpbot_video_is_youtube && $_wpbot_youtube_embed_src !== '' ) : ?>
270 - <iframe class="wpbot-icon-video" src="<?php echo $_wpbot_video_delay_ms > 0 ? 'about:blank' : esc_url( $_wpbot_youtube_embed_src ); ?>" data-wpbot-yt-src="<?php echo esc_url( $_wpbot_youtube_embed_src ); ?>" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture"></iframe>
271 - <?php elseif ( ! $_wpbot_video_is_youtube ) : ?>
272 - <video class="wpbot-icon-video" src="<?php echo esc_url( $_wpbot_icon_video ); ?>" autoplay muted loop playsinline preload="auto"></video>
273 - <?php endif; ?>
274 - <?php endif; ?>
148 + alt="wpChatIcon" qcld_agent="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>" >
149 +
275 150 </div>
276 -
277 151 </div>
278 - <?php
279 - if ( $_wpbot_icon_video !== '' ) :
280 - ?>
281 - <script>
282 - (function(){
283 - var wpbotDelay = <?php echo (int) $_wpbot_video_delay_ms; ?>;
284 - function wpbotForcePlay(){
285 - var v = document.querySelector('#wp-chatbot-ball video.wpbot-icon-video');
286 - if( v ){
287 - v.muted = true;
288 - v.volume = 0;
289 - v.loop = true;
290 - var tries = 0, maxTries = 30;
291 - var timer = setInterval(function(){
292 - tries++;
293 - v.play().then(function(){ clearInterval(timer); }).catch(function(){});
294 - if( tries >= maxTries ) clearInterval(timer);
295 - }, 300);
296 - }
297 - var yt = document.querySelector('#wp-chatbot-ball iframe.wpbot-icon-video');
298 - if( yt ){
299 - var ytSrc = yt.getAttribute('data-wpbot-yt-src');
300 - if( ytSrc && ( !yt.getAttribute('src') || yt.getAttribute('src') === 'about:blank' || yt.getAttribute('src').indexOf('autoplay=1') === -1 ) ){
301 - yt.setAttribute('src', ytSrc);
302 - }
303 - }
304 - }
305 - function wpbotDelayedPlay(){
306 - setTimeout(wpbotForcePlay, wpbotDelay);
307 - }
308 - if( document.readyState === 'loading' ){
309 - document.addEventListener('DOMContentLoaded', wpbotDelayedPlay);
310 - } else {
311 - wpbotDelayedPlay();
312 - }
313 - window.addEventListener('load', function(){
314 - setTimeout(wpbotForcePlay, wpbotDelay);
315 - });
316 - })();
317 - </script>
318 - <?php endif; ?>
319 152 <?php
320 153 $fb_app_id = get_option('qlcd_wp_chatbot_fb_app_id');
321 154 $fb_page_id = get_option('qlcd_wp_chatbot_fb_page_id');
322 155 $fb_mgs_color = get_option('qlcd_wp_chatbot_fb_color') != '' ? get_option('qlcd_wp_chatbot_fb_color') : '#0084ff';
@@ -359,11 +192,11 @@
359 192 </div>
360 193
361 194 <?php
362 195
363 - if ( get_transient( 'qcld_bot_clear_cache' ) ) {
196 + if ( get_transient( 'bot_clear_cache' ) ) {
364 197 echo '<script type="text/javascript">var wpbot_clear_cache = 1 </script>';
365 - delete_transient( 'qcld_bot_clear_cache' );
198 + delete_transient( 'bot_clear_cache' );
366 199 }
367 200
368 201 }else{
369 202 ?>
@@ -433,9 +266,9 @@
433 266 return $wp_chatbot_load;
434 267 }
435 268 //checking Devices
436 269 function wp_chatbot_is_mobile(){
437 - $useragent = isset( $_SERVER['HTTP_USER_AGENT'] ) ? $_SERVER['HTTP_USER_AGENT'] : '';
270 + $useragent = $_SERVER['HTTP_USER_AGENT'];
438 271 if (preg_match('/(android|bb\d+|meego).+mobile|avantgo|bada\/|blackberry|blazer|compal|elaine|fennec|hiptop|iemobile|ip(hone|od)|iris|kindle|lge |maemo|midp|mmp|netfront|opera m(ob|in)i|palm( os)?|phone|p(ixi|re)\/|plucker|pocket|psp|series(4|6)0|symbian|treo|up\.(browser|link)|vodafone|wap|windows (ce|phone)|xda|xiino/i', $useragent) || preg_match('/1207|6310|6590|3gso|4thp|50[1-6]i|770s|802s|a wa|abac|ac(er|oo|s\-)|ai(ko|rn)|al(av|ca|co)|amoi|an(ex|ny|yw)|aptu|ar(ch|go)|as(te|us)|attw|au(di|\-m|r |s )|avan|be(ck|ll|nq)|bi(lb|rd)|bl(ac|az)|br(e|v)w|bumb|bw\-(n|u)|c55\/|capi|ccwa|cdm\-|cell|chtm|cldc|cmd\-|co(mp|nd)|craw|da(it|ll|ng)|dbte|dc\-s|devi|dica|dmob|do(c|p)o|ds(12|\-d)|el(49|ai)|em(l2|ul)|er(ic|k0)|esl8|ez([4-7]0|os|wa|ze)|fetc|fly(\-|_)|g1 u|g560|gene|gf\-5|g\-mo|go(\.w|od)|gr(ad|un)|haie|hcit|hd\-(m|p|t)|hei\-|hi(pt|ta)|hp( i|ip)|hs\-c|ht(c(\-| |_|a|g|p|s|t)|tp)|hu(aw|tc)|i\-(20|go|ma)|i230|iac( |\-|\/)|ibro|idea|ig01|ikom|im1k|inno|ipaq|iris|ja(t|v)a|jbro|jemu|jigs|kddi|keji|kgt( |\/)|klon|kpt |kwc\-|kyo(c|k)|le(no|xi)|lg( g|\/(k|l|u)|50|54|\-[a-w])|libw|lynx|m1\-w|m3ga|m50\/|ma(te|ui|xo)|mc(01|21|ca)|m\-cr|me(rc|ri)|mi(o8|oa|ts)|mmef|mo(01|02|bi|de|do|t(\-| |o|v)|zz)|mt(50|p1|v )|mwbp|mywa|n10[0-2]|n20[2-3]|n30(0|2)|n50(0|2|5)|n7(0(0|1)|10)|ne((c|m)\-|on|tf|wf|wg|wt)|nok(6|i)|nzph|o2im|op(ti|wv)|oran|owg1|p800|pan(a|d|t)|pdxg|pg(13|\-([1-8]|c))|phil|pire|pl(ay|uc)|pn\-2|po(ck|rt|se)|prox|psio|pt\-g|qa\-a|qc(07|12|21|32|60|\-[2-7]|i\-)|qtek|r380|r600|raks|rim9|ro(ve|zo)|s55\/|sa(ge|ma|mm|ms|ny|va)|sc(01|h\-|oo|p\-)|sdk\/|se(c(\-|0|1)|47|mc|nd|ri)|sgh\-|shar|sie(\-|m)|sk\-0|sl(45|id)|sm(al|ar|b3|it|t5)|so(ft|ny)|sp(01|h\-|v\-|v )|sy(01|mb)|t2(18|50)|t6(00|10|18)|ta(gt|lk)|tcl\-|tdg\-|tel(i|m)|tim\-|t\-mo|to(pl|sh)|ts(70|m\-|m3|m5)|tx\-9|up(\.b|g1|si)|utst|v400|v750|veri|vi(rg|te)|vk(40|5[0-3]|\-v)|vm40|voda|vulc|vx(52|53|60|61|70|80|81|83|85|98)|w3c(\-| )|webc|whit|wi(g |nc|nw)|wmlb|wonu|x700|yas\-|your|zeto|zte\-/i', substr($useragent, 0, 4))) {
439 272 return true;
440 273 } else {
441 274 return false;
@@ -442,10 +275,10 @@
442 275 }
443 276 }
444 277 //Checking wpwbot opening hour
445 278 function wp_chatbot_check_opening_hours(){
446 - $curent_day=strtolower(gmdate('l',strtotime(current_time( 'mysql' ))));
447 - $current_time=gmdate('H:i',strtotime(current_time( 'mysql')));
279 + $curent_day=strtolower(date('l',strtotime(current_time( 'mysql' ))));
280 + $current_time=date('H:i',strtotime(current_time( 'mysql')));
448 281 $is_wpwbot_open =false;
449 282 if(get_option('wpwbot_hours')) {
450 283 $wpwbot_times = wp_kses_post(unserialize(get_option('wpwbot_hours')));
451 284 if (isset($wpwbot_times[$curent_day])) {
@@ -460,8 +293,183 @@
460 293 }
461 294 }
462 295 return $is_wpwbot_open;
463 296 }
297 +//wpwBot shortcode.
298 +add_shortcode('wpwbot', 'wp_chatbot_short_code');
299 +function wp_chatbot_short_code($atts = []){
300 + ob_start();
301 + wp_chatbot_shortcode_dom($atts);
302 + $content = ob_get_clean();
303 + return $content;
304 +}
305 +function wp_chatbot_shortcode_dom($atts){
306 + //Defaults & Set Parameters for shortcode
307 + extract(shortcode_atts(
308 + array(
309 + 'template' => '01',
310 + ), $atts
311 + ));
312 + ?>
313 + <style>
314 + <?php if(get_option('wp_chatbot_custom_css')!=""){echo sanitize_text_field(get_option('wp_chatbot_custom_css')); } ?>
315 + </style>
316 + <?php if (get_option('qcld_wb_chatbot_change_bg') == 1) {
317 + if (get_option('qcld_wb_chatbot_board_bg_path') != "") {
318 + $qcld_wb_chatbot_board_bg_path = get_option('qcld_wb_chatbot_board_bg_path');
319 + } else {
320 + $qcld_wb_chatbot_board_bg_path = QCLD_wpCHATBOT_IMG_URL . 'background/background.png';
321 + }
322 + ?>
323 + <style>
324 + .wp-chatbot-container {
325 + background: url(<?php echo esc_url($qcld_wb_chatbot_board_bg_path) ;?>) no-repeat top right !important;
326 + }
327 + </style>
328 +<?php }
329 + $wp_chatbot_enable_rtl = "";
330 + if (get_option('enable_wp_chatbot_rtl')) {
331 + $wp_chatbot_enable_rtl .= "wp-chatbot-rtl";
332 + }
333 + ?>
334 + <div id="wp-chatbot-chat-container" class="<?php echo esc_attr($wp_chatbot_enable_rtl); ?>">
335 + <?php
336 + //Get wpcommerce cart
337 +
338 + $qcld_wb_chatbot_theme = 'template-' . $template;
339 + if (file_exists(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/style.css')) {
340 + wp_register_style('qcld-wp-chatbot-style', plugins_url(basename(plugin_dir_path(__FILE__)) . '/templates/' . $qcld_wb_chatbot_theme . '/style.css', basename(__FILE__)), '', QCLD_wpCHATBOT_VERSION, 'screen');
341 + wp_enqueue_style('qcld-wp-chatbot-style');
342 + }
343 + if (file_exists(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/template.php')) {
344 + require_once(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/template.php');
345 + } else {
346 + echo "<h2>" . __('No wpWBot Theme Found!', 'wpchatbot') . "</h2>";
347 + }
348 + ?>
349 + <?php if (get_option('disable_wp_chatbot') != 1): ?>
350 + <div id="wp-chatbot-notification-container" class="wp-chatbot-notification-container">
351 + <div class="wp-chatbot-notification-controller"> <span class="wp-chatbot-notification-close">X</span> </div>
352 + <?php
353 + if (get_option('wp_chatbot_custom_agent_path') != "" && get_option('wp_chatbot_agent_image') == "custom-agent.png") {
354 + $wp_chatbot_custom_icon_path = get_option('wp_chatbot_custom_agent_path');
355 + } else if (get_option('wp_chatbot_custom_agent_path') != "" && get_option('wp_chatbot_agent_image') != "custom-agent.png") {
356 + $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_agent_image');
357 + } else {
358 + $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . 'custom-agent.png';
359 + }
360 + ?>
361 + <div class="wp-chatbot-notification-agent-profile">
362 + <div class="wp-chatbot-notification-widget-avatar"><img
363 + src="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>" alt=""></div>
364 + <div class="wp-chatbot-notification-welcome"><?php echo wp_kses_post(wpb_randmom_message_handle(maybe_unserialize(get_option('qlcd_wp_chatbot_welcome')))) . ' <strong>' . esc_html(get_option('qlcd_wp_chatbot_host')) . '</strong>'; ?></div>
365 + </div>
366 + <div class="wp-chatbot-notification-message"><?php echo wp_kses_post(wpb_randmom_message_handle(maybe_unserialize(get_option('qlcd_wp_chatbot_notifications')))); ?></div>
367 + </div>
368 + <!--wp-chatbot-board-container-->
369 + <div id="wp-chatbot-ball" class="">
370 + <div class="wp-chatbot-ball">
371 + <div class="wp-chatbot-ball-animator wp-chatbot-ball-animation-switch"></div>
372 + <?php
373 + if (get_option('wp_chatbot_custom_icon_path') != "" && get_option('wp_chatbot_icon') == "custom.png") {
374 + $wp_chatbot_custom_icon_path = get_option('wp_chatbot_custom_icon_path');
375 + } else if (get_option('wp_chatbot_custom_icon_path') != "" && get_option('wp_chatbot_icon') != "custom.png") {
376 + $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_icon');
377 + } else {
378 + $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . 'custom.png';
379 + }
380 + ?>
381 + <img src="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>"
382 + alt="wpChatIcon"> <!--<span class="wp-chatbot-ball-cart-items"><?php echo $cart_items_number; ?></span>--> </div>
383 + </div>
384 + <!-- wp-chatbot-board-container-->
385 + <?php endif; ?>
386 + <!--container-->
387 + <!--wp-chatbot-ball-wrapper-->
388 + </div>
389 +<?php } ?>
390 +<?php
391 +//Create shortcode for wpwBot for pages.
392 +add_shortcode('wpbot-page', 'wp_chatbot_page_short_code');
393 +function wp_chatbot_page_short_code(){
394 + ob_start();
395 + wp_chatbot_page_dom();
396 + $content = ob_get_clean();
397 + return $content;
398 +}
399 +function wp_chatbot_page_dom(){ ?>
400 + <style>
401 + <?php if(get_option('wp_chatbot_custom_css')!=""){echo sanitize_text_field(get_option('wp_chatbot_custom_css')); } ?>
402 + </style>
403 + <?php
404 + //Get wpcommerce cart
405 +
406 + $qcld_wb_chatbot_theme = get_option('qcld_wb_chatbot_theme');
407 + $wp_chatbot_enable_rtl = "";
408 + if (get_option('enable_wp_chatbot_rtl') == 1) {
409 + $wp_chatbot_enable_rtl .= "wp-chatbot-rtl";
410 + }
411 + if (file_exists(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/shortcode.php')) {
412 + require_once(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/shortcode.php');
413 + } else {
414 + echo "<h2>" . __('No WPBot ShortCode Theme Found!', 'wpchatbot') . "</h2>";
415 + }
416 +}
417 +//shortcode for wpWBot mobile app
418 +add_shortcode('wpwbot_app', 'wp_chatbot_mobile_app_short_code');
419 +function wp_chatbot_mobile_app_short_code(){ ?>
420 + <style>
421 + <?php if(get_option('wp_chatbot_custom_css')!=""){echo sanitize_text_field(get_option('wp_chatbot_custom_css')); } ?>
422 + </style>
423 + <?php if (get_option('qcld_wb_chatbot_change_bg') == 1) {
424 + if (get_option('qcld_wb_chatbot_board_bg_path') != "") {
425 + $qcld_wb_chatbot_board_bg_path = get_option('qcld_wb_chatbot_board_bg_path');
426 + } else {
427 + $qcld_wb_chatbot_board_bg_path = QCLD_wpCHATBOT_IMG_URL . 'background/background.png';
428 + }
429 + ?>
430 + <style>
431 + .wp-chatbot-container {
432 + background: url(<?php echo esc_url($qcld_wb_chatbot_board_bg_path) ;?>) no-repeat top right !important;
433 + }
434 + </style>
435 +<?php }
436 + $wp_chatbot_enable_rtl = "";
437 + if (get_option('enable_wp_chatbot_rtl') == '1') {
438 + $wp_chatbot_enable_rtl .= "wp-chatbot-rtl";
439 + }
440 + ?>
441 + <div id="wp-chatbot-chat-app-shortcode-container" class="<?php echo esc_attr($wp_chatbot_enable_rtl); ?>">
442 + <?php
443 + // keep traking app template.
444 + $template_app = 'yes';
445 + //Get wpcommerce cart
446 +
447 + //Handling shortcode enqeue and remove features part.
448 + define('wpCOMMERCE', true);
449 + wp_enqueue_script('jquery');
450 +
451 +
452 + wp_enqueue_script('wc-address-i18n');
453 + wp_enqueue_script('wc-country-select');
454 +
455 +
456 + // add the action
457 + if (isset($_GET['from']) && $_GET['from'] == 'app') {
458 + if (!isset($_COOKIE['from_app'])) {
459 + setcookie('from_app', 'yes', time() + 3600);
460 + }
461 + }
462 + $qcld_wb_chatbot_theme = get_option('qcld_wb_chatbot_theme');
463 + if (file_exists(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/template.php')) {
464 + require_once(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/template.php');
465 + } else {
466 + echo "<h2>" . __('No WPBot Theme Found!', 'wpchatbot') . "</h2>";
467 + }
468 + ?>
469 + </div>
470 + <?php
471 +}
464 472
465 473 /**
466 474 * wpwBot Search keyword product
467 475 */
@@ -467,16 +475,9 @@
467 475 */
468 476 add_action('wp_ajax_qcld_wb_chatbot_keyword', 'qcld_wb_chatbot_keyword');
469 477 add_action('wp_ajax_nopriv_qcld_wb_chatbot_keyword', 'qcld_wb_chatbot_keyword');
470 478 function qcld_wb_chatbot_keyword(){
471 - // Verify nonce for security
472 - $nonce = isset($_POST['security']) ? sanitize_text_field(wp_unslash($_POST['security'])) : (isset($_POST['nonce']) ? sanitize_text_field(wp_unslash($_POST['nonce'])) : '');
473 - if ( ! wp_verify_nonce( $nonce, 'wp_chatbot' ) && ! wp_verify_nonce( $nonce, 'qcsecretbotnonceval123qc' ) ) {
474 - wp_send_json_error( array( 'status' => 'fail', 'message' => 'Security check failed.' ) );
475 - wp_die();
476 - }
477 -
478 - $keyword = sanitize_text_field(wp_unslash($_POST['keyword']));
479 + $keyword = sanitize_text_field($_POST['keyword']);
479 480 $product_per_page = get_option('qlcd_wp_chatbot_ppp') != '' ? get_option('qlcd_wp_chatbot_ppp') : 10;
480 481 if (get_option('qlcd_wp_chatbot_search_option') == 'standard') {
481 482 $product_orderby = sanitize_text_field(get_option('qlcd_wp_chatbot_product_orderby') != '' ? get_option('qlcd_wp_chatbot_product_orderby') : 'title');
482 483 $product_order = sanitize_text_field(get_option('qlcd_wp_chatbot_product_order') != '' ? get_option('qlcd_wp_chatbot_product_order') : 'ASC');
@@ -522,9 +523,9 @@
522 523 endwhile;
523 524 wp_reset_postdata();
524 525 $html .= '</ul>';
525 526 if ($total_product_num > $product_per_page && $product_per_page > 0 ) {
526 - $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . esc_attr($keyword) . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
527 + $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . $keyword . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
527 528 }
528 529 }
529 530 $html .= '</div>';
530 531 } else if (get_option('qlcd_wp_chatbot_search_option') == 'advanced') {
@@ -552,9 +553,9 @@
552 553 }
553 554 }
554 555 $html .= '</ul>';
555 556 if ($total_product_num > $product_per_page && $product_per_page > 0) {
556 - $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . esc_attr($more_product_ids) . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
557 + $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . $more_product_ids . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
557 558 }
558 559 }
559 560 $html .= '</div>';
560 561 }
@@ -569,15 +570,16 @@
569 570 add_action('wp_ajax_nopriv_qcld_wb_chatbot_category', 'qcld_wb_chatbot_category');
570 571 function qcld_wb_chatbot_category(){
571 572 $category_type="common";
572 573 if (get_option('wp_chatbot_show_parent_category') != "") {
573 - $terms = get_terms( array( 'taxonomy' => 'product_cat', 'parent' => 0, 'hide_empty' => true, 'fields' => 'all' ) );
574 + $terms = get_terms('product_cat', array('parent' => 0, 'hide_empty' => true, 'fields' => 'all'));
575 +
574 576 } else {
575 - $terms = get_terms( array( 'taxonomy' => 'product_cat', 'hide_empty' => true, 'fields' => 'all' ) );
577 + $terms = get_terms('product_cat', array('hide_empty' => true, 'fields' => 'all'));
576 578 }
577 579 $html = "";
578 580 foreach ($terms as $term) {
579 - $child_terms=get_terms( array( 'taxonomy' => 'product_cat', 'parent' => $term->term_id, 'hide_empty' => true, 'fields' => 'all' ) );
581 + $child_terms=get_terms('product_cat', array('parent' => $term->term_id, 'hide_empty' => true, 'fields' => 'all'));
580 582 if(get_option('wp_chatbot_show_sub_category')==1 && count($child_terms) >0){
581 583 $category_type="hasChilds";
582 584 }
583 585 $html .= '<span class="qcld-chatbot-product-category" data-category-type="' . $category_type . '" data-category-slug="' . $term->slug . '" data-category-id="' . $term->term_id . '">' . $term->name . '</span>';
@@ -590,10 +592,10 @@
590 592 */
591 593 add_action('wp_ajax_qcld_wb_chatbot_sub_category', 'qcld_wb_chatbot_sub_category');
592 594 add_action('wp_ajax_nopriv_qcld_wb_chatbot_sub_category', 'qcld_wb_chatbot_sub_category');
593 595 function qcld_wb_chatbot_sub_category(){
594 - $parent_id = intval( wp_unslash( $_POST['parent_id'] ) );
595 - $terms = get_terms( array( 'taxonomy' => 'product_cat', 'parent' => $parent_id, 'hide_empty' => true, 'fields' => 'all' ) );
596 + $parent_id = stripslashes($_POST['parent_id']);
597 + $terms = get_terms('product_cat', array('parent' => $parent_id, 'hide_empty' => true, 'fields' => 'all'));
596 598 $html = "";
597 599 foreach ($terms as $term) {
598 600 $html .= '<span class="qcld-chatbot-product-category" data-category-type="common" data-category-slug="' . $term->slug . '" data-category-id="' . $term->term_id . '">' . $term->name . '</span>';
599 601 }
@@ -605,9 +607,9 @@
605 607 */
606 608 add_action('wp_ajax_qcld_wb_chatbot_category_products', 'qcld_wb_chatbot_category_products');
607 609 add_action('wp_ajax_nopriv_qcld_wb_chatbot_category_products', 'qcld_wb_chatbot_category_products');
608 610 function qcld_wb_chatbot_category_products(){
609 - $category_id = intval( wp_unslash( $_POST['category'] ) );
611 + $category_id = stripslashes($_POST['category']);
610 612 $product_per_page = sanitize_text_field(get_option('qlcd_wp_chatbot_ppp') != '' ? get_option('qlcd_wp_chatbot_ppp') : 10);
611 613 $product_orderby = sanitize_text_field(get_option('qlcd_wp_chatbot_product_orderby') != '' ? get_option('qlcd_wp_chatbot_product_orderby') : 'title');
612 614 $product_order = sanitize_text_field(get_option('qlcd_wp_chatbot_product_order') != '' ? get_option('qlcd_wp_chatbot_product_order') : 'ASC');
613 615 //Merging all query together.
@@ -844,11 +846,11 @@
844 846 //load more
845 847 add_action('wp_ajax_qcld_wb_chatbot_load_more', 'qcld_wb_chatbot_load_more');
846 848 add_action('wp_ajax_nopriv_qcld_wb_chatbot_load_more', 'qcld_wb_chatbot_load_more');
847 849 function qcld_wb_chatbot_load_more(){
848 - $offset = intval( wp_unslash( $_POST['offset'] ) );
849 - $search_type = sanitize_text_field( wp_unslash( $_POST['search_type'] ) );
850 - $search_term = sanitize_text_field( wp_unslash( $_POST['search_term'] ) );
850 + $offset = stripslashes($_POST['offset']);
851 + $search_type = stripslashes($_POST['search_type']);
852 + $search_term = stripslashes($_POST['search_term']);
851 853 $product_per_page = sanitize_text_field(get_option('qlcd_wp_chatbot_ppp') != '' ? get_option('qlcd_wp_chatbot_ppp') : 10);
852 854 $product_orderby = sanitize_text_field(get_option('qlcd_wp_chatbot_product_orderby') != '' ? get_option('qlcd_wp_chatbot_product_orderby') : 'title');
853 855 $product_order = sanitize_text_field(get_option('qlcd_wp_chatbot_product_order') != '' ? get_option('qlcd_wp_chatbot_product_order') : 'ASC');
854 856 $next_offset = intval($product_per_page + $offset);
@@ -979,9 +981,9 @@
979 981 //product details
980 982 add_action('wp_ajax_qcld_wb_chatbot_product_details', 'qcld_wb_chatbot_product_details');
981 983 add_action('wp_ajax_nopriv_qcld_wb_chatbot_product_details', 'qcld_wb_chatbot_product_details');
982 984 function qcld_wb_chatbot_product_details(){
983 - $product_id = intval( wp_unslash( $_POST['wp_chatbot_pid'] ) );
985 + $product_id = stripslashes($_POST['wp_chatbot_pid']);
984 986 //Tracking product view from chat board
985 987 wp_chatbot_view_track_product_by_id($product_id);
986 988 //wpcommerce product factory
987 989 $wc_pf = new WC_Product_Factory();
@@ -1009,9 +1011,9 @@
1009 1011 }
1010 1012 }
1011 1013 $product_image .= '</ul></div>';
1012 1014 $product_price = '<p class="wp-chatbot-product-price" id="wp-chatbot-product-price">' . $product->get_price_html() . '</p>';
1013 - $product_sku = '<p class="wp-chatbot-product-sku"> ' . __('SKU', 'chatbot') . ' : ' . $product->get_sku() . '</p>';
1015 + $product_sku = '<p class="wp-chatbot-product-sku"> ' . __('SKU', 'wpchatbot') . ' : ' . $product->get_sku() . '</p>';
1014 1016 //if ( $product->is_in_stock() || $product->is_purchasable() )
1015 1017 //Handle variable product start
1016 1018 $variations = "";
1017 1019 $add_cart_button = "";
@@ -1054,11 +1056,10 @@
1054 1056 $variations .= '<label for="' . sanitize_title($name) . '">' . $title . '</label>';
1055 1057 $variations .= '<select id="' . esc_attr(sanitize_title($name)) . '" name="attribute_' . sanitize_title($name) . '" data-attribute_name="attribute_' . sanitize_title($name) . '" class="each_attribute">';
1056 1058 $variations .= '<option value="">' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_choose_option')))) . '</option>';
1057 1059 foreach ($values as $value) {
1058 - $attr_key = 'attribute_' . sanitize_title( $name );
1059 - if ( isset( $_REQUEST[ $attr_key ] ) ) { // phpcs:ignore WordPress.Security.NonceVerification
1060 - $selected_value = sanitize_text_field( wp_unslash( $_REQUEST[ $attr_key ] ) );
1060 + if (isset($_REQUEST['attribute_' . sanitize_title($name)])) {
1061 + $selected_value = $_REQUEST['attribute_' . sanitize_title($name)];
1061 1062 } else {
1062 1063 $selected_value = '';
1063 1064 }
1064 1065 $variations .= '<option value="' . esc_attr(strtolower($value)) . '"' . selected($selected_value, $value, false) . '>' . apply_filters('wpcommerce_variation_option_name', $value) . '</option>';
@@ -1079,15 +1080,15 @@
1079 1080 $response = array('title' => $product_title, 'description' => $product_desc, 'image' => $product_image, 'price' => $product_price, 'sku' => $product_sku, 'quantity' => $product_quantity, 'buttton' => $add_cart_button, 'variation' => $variations, 'type' => $product_type, 'debug' => $debug);
1080 1081 wp_send_json($response);
1081 1082 }
1082 1083 //Add to cart for variable product.
1083 -add_action('wp_ajax_qcld_variable_add_to_cart', 'qcld_variable_add_to_cart');
1084 -add_action('wp_ajax_nopriv_qcld_variable_add_to_cart', 'qcld_variable_add_to_cart');
1085 -function qcld_variable_add_to_cart(){
1086 - $product_id = intval( wp_unslash( $_POST['p_id'] ) );
1087 - $quantity = intval( wp_unslash( $_POST['quantity'] ) );
1088 - $variations_id = intval( wp_unslash( $_POST['variations_id'] ) );
1089 - $attrs = isset( $_POST['attributes'] ) ? array_map( 'sanitize_text_field', wp_unslash( (array) $_POST['attributes'] ) ) : array();
1084 +add_action('wp_ajax_variable_add_to_cart', 'qcld_wb_chatbot_variable_add_to_cart');
1085 +add_action('wp_ajax_nopriv_variable_add_to_cart', 'qcld_wb_chatbot_variable_add_to_cart');
1086 +function qcld_wb_chatbot_variable_add_to_cart(){
1087 + $product_id = stripslashes($_POST['p_id']);
1088 + $quantity = stripslashes($_POST['quantity']);
1089 + $variations_id = stripslashes($_POST['variations_id']);
1090 + $attrs = stripslashes($_POST['attributes']);
1090 1091 //echo wp_send_json(array('p_id'=>$product_id,'qnty'=>$quantity,'id'=>$variations_id,'att'=>$attrs));
1091 1092 $attributes = array();
1092 1093 foreach ($attrs as $attr) {
1093 1094 $single = explode("#", $attr);
@@ -1107,10 +1108,10 @@
1107 1108 //Add to cart for simple product.
1108 1109 add_action('wp_ajax_qcld_wb_chatbot_add_to_cart', 'qcld_wb_chatbot_add_to_cart');
1109 1110 add_action('wp_ajax_nopriv_qcld_wb_chatbot_add_to_cart', 'qcld_wb_chatbot_add_to_cart');
1110 1111 function qcld_wb_chatbot_add_to_cart(){
1111 - $product_id = intval( wp_unslash( $_POST['product_id'] ) );
1112 - $product_quantity = intval( wp_unslash( $_POST['quantity'] ) );
1112 + $product_id = stripslashes($_POST['product_id']);
1113 + $product_quantity = stripslashes($_POST['quantity']);
1113 1114 global $wpcommerce;
1114 1115 $result = $wpcommerce->cart->add_to_cart($product_id, $product_quantity);
1115 1116 if ($result != false) {
1116 1117 wp_send_json('simple');
@@ -1121,19 +1122,15 @@
1121 1122 //Support part
1122 1123 add_action('wp_ajax_qcld_wb_chatbot_support_email', 'qcld_wb_chatbot_support_email');
1123 1124 add_action('wp_ajax_nopriv_qcld_wb_chatbot_support_email', 'qcld_wb_chatbot_support_email');
1124 1125 function qcld_wb_chatbot_support_email(){
1125 - $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( wp_unslash( $_POST['nonce'] ) ) : '';
1126 - if ( ! wp_verify_nonce( $nonce, 'qcsecretbotnonceval123qc' ) ) {
1127 - wp_send_json_error( array( 'error' => esc_html__( 'Error: Invalid nonce verification.', 'chatbot' ) ) );
1128 - }
1129 - $name = trim(sanitize_text_field(wp_unslash($_POST['name'])));
1130 - $email = sanitize_email(wp_unslash($_POST['email']));
1131 - $message = sanitize_text_field(wp_unslash($_POST['message']));
1126 + $name = trim(sanitize_text_field($_POST['name']));
1127 + $email = sanitize_email($_POST['email']);
1128 + $message = sanitize_text_field($_POST['message']);
1132 1129 $subject = sanitize_text_field(get_option('qlcd_wp_chatbot_email_sub') != '' ? get_option('qlcd_wp_chatbot_email_sub') : 'Support Email from wpWBot by Client');
1133 1130 //Extract Domain
1134 1131 $url = get_site_url();
1135 - $url = wp_parse_url($url);
1132 + $url = parse_url($url);
1136 1133 $domain = $url['host'];
1137 1134 //$admin_email = "admin@" . $domain;
1138 1135 $admin_email = sanitize_email(get_option('admin_email'));
1139 1136 $toEmail = sanitize_email(get_option('qlcd_wp_chatbot_admin_email') != '' ? get_option('qlcd_wp_chatbot_admin_email') : $admin_email);
@@ -1143,8 +1140,9 @@
1143 1140 $fromEmail = get_option('qlcd_wp_chatbot_from_email');
1144 1141 }else{
1145 1142 $fromEmail = "wordpress@" . $domain;
1146 1143 }
1144 +
1147 1145 //Starting messaging and status.
1148 1146 $response['status'] = 'fail';
1149 1147 $response['message'] = str_replace('\\', '',wp_kses_post(get_option('qlcd_wp_chatbot_email_fail')));
1150 1148 if (filter_var($email, FILTER_VALIDATE_EMAIL) === false) {
@@ -1152,14 +1150,14 @@
1152 1150 $response['status'] = 'fail';
1153 1151 } else {
1154 1152 //build email body
1155 1153 $bodyContent = "";
1156 - $bodyContent .= '<p><strong>' . __('Support Request Details', 'chatbot') . ':</strong></p><hr>';
1157 - $bodyContent .= '<p>' . __('Name', 'chatbot') . ' : ' . $name . '</p>';
1158 - $bodyContent .= '<p>' . __('Email', 'chatbot') . ' : ' . $email . '</p>';
1159 - $bodyContent .= '<p>' . __('Subject', 'chatbot') . ' : ' . $subject . '</p>';
1160 - $bodyContent .= '<p>' . __('Message', 'chatbot') . ' : ' . $message . '</p>';
1161 - $bodyContent .= '<p>' . __('Mail Generated on', 'chatbot') . ': ' . current_time('F j, Y, g:i a') . '</p>';
1154 + $bodyContent .= '<p><strong>' . __('Support Request Details', 'wpchatbot') . ':</strong></p><hr>';
1155 + $bodyContent .= '<p>' . __('Name', 'wpchatbot') . ' : ' . $name . '</p>';
1156 + $bodyContent .= '<p>' . __('Email', 'wpchatbot') . ' : ' . $email . '</p>';
1157 + $bodyContent .= '<p>' . __('Subject', 'wpchatbot') . ' : ' . $subject . '</p>';
1158 + $bodyContent .= '<p>' . __('Message', 'wpchatbot') . ' : ' . $message . '</p>';
1159 + $bodyContent .= '<p>' . __('Mail Generated on', 'wpchatbot') . ': ' . current_time('F j, Y, g:i a') . '</p>';
1162 1160 $to = $toEmail;
1163 1161 $body = $bodyContent;
1164 1162 $headers = array();
1165 1163 $headers[] = 'Content-Type: text/html; charset=UTF-8';
@@ -1171,9 +1169,9 @@
1171 1169 $response['message'] = str_replace('\\', '',wp_kses_post(get_option('qlcd_wp_chatbot_email_sent')));
1172 1170 }
1173 1171
1174 1172 }
1175 - echo wp_json_encode($response);
1173 + echo json_encode($response);
1176 1174 die();
1177 1175 }
1178 1176 //Support Phone
1179 1177 add_action('wp_ajax_qcld_wb_chatbot_support_phone', 'qcld_wb_chatbot_support_phone');
@@ -1178,15 +1176,14 @@
1178 1176 //Support Phone
1179 1177 add_action('wp_ajax_qcld_wb_chatbot_support_phone', 'qcld_wb_chatbot_support_phone');
1180 1178 add_action('wp_ajax_nopriv_qcld_wb_chatbot_support_phone', 'qcld_wb_chatbot_support_phone');
1181 1179 function qcld_wb_chatbot_support_phone(){
1182 - check_ajax_referer('qcsecretbotnonceval123qc', 'nonce');
1183 - $name = trim(sanitize_text_field(wp_unslash($_POST['name'])));
1184 - $phone =sanitize_text_field(wp_unslash($_POST['phone']));
1180 + $name = trim(sanitize_text_field($_POST['name']));
1181 + $phone =sanitize_text_field($_POST['phone']);
1185 1182 $subject = 'WPBot Support Mail Request for Call Back';
1186 1183 //Extract Domain
1187 1184 $url = get_site_url();
1188 - $url = wp_parse_url($url);
1185 + $url = parse_url($url);
1189 1186 $domain = $url['host'];
1190 1187 //$admin_email = "admin@" . $domain;
1191 1188 $admin_email = get_option('admin_email');
1192 1189 $toEmail = sanitize_email(get_option('qlcd_wp_chatbot_admin_email') != '' ? get_option('qlcd_wp_chatbot_admin_email') : $admin_email);
@@ -1201,14 +1198,14 @@
1201 1198 $response['status'] = 'fail';
1202 1199 $response['message'] = str_replace('\\', '',wp_kses_post(get_option('qlcd_wp_chatbot_phone_fail')));
1203 1200 //build email body
1204 1201 $bodyContent = "";
1205 - $bodyContent .= '<p><strong>' . __('Support Request Details', 'chatbot') . ':</strong></p><hr>';
1206 - $bodyContent .= '<p>' . __('Name', 'chatbot') . ' : ' . $name . '</p>';
1207 - $bodyContent .= '<p>' . __('Phone', 'chatbot') . ' : ' . $phone . '</p>';
1208 - $bodyContent .= '<p>' . __('Subject', 'chatbot') . ' : ' . $subject . '</p>';
1209 - $bodyContent .= '<p>' . __('Message', 'chatbot') . ' : ' . __(' Call me at ', 'chatbot'). $phone . '</p>';
1210 - $bodyContent .= '<p>' . __('Mail Generated on', 'chatbot') . ': ' . current_time('F j, Y, g:i a') . '</p>';
1202 + $bodyContent .= '<p><strong>' . __('Support Request Details', 'wpchatbot') . ':</strong></p><hr>';
1203 + $bodyContent .= '<p>' . __('Name', 'wpchatbot') . ' : ' . $name . '</p>';
1204 + $bodyContent .= '<p>' . __('Phone', 'wpchatbot') . ' : ' . $phone . '</p>';
1205 + $bodyContent .= '<p>' . __('Subject', 'wpchatbot') . ' : ' . $subject . '</p>';
1206 + $bodyContent .= '<p>' . __('Message', 'wpchatbot') . ' : ' . __(' Call me at ', 'wpchatbot'). $phone . '</p>';
1207 + $bodyContent .= '<p>' . __('Mail Generated on', 'wpchatbot') . ': ' . current_time('F j, Y, g:i a') . '</p>';
1211 1208 $to = $toEmail;
1212 1209 $body = $bodyContent;
1213 1210 $headers = array();
1214 1211 $headers[] = 'Content-Type: text/html; charset=UTF-8';
@@ -1218,15 +1215,15 @@
1218 1215 if ($result) {
1219 1216 $response['status'] = 'success';
1220 1217 $response['message'] = str_replace('\\', '',wp_kses_post(get_option('qlcd_wp_chatbot_phone_sent')));
1221 1218 }
1222 - echo wp_json_encode($response);
1219 + echo json_encode($response);
1223 1220 die();
1224 1221 }
1225 1222 // Order Status part. removed
1226 1223
1227 1224 function wpb_randmom_message_handle($items){
1228 - return $items[wp_rand(0, count($items) - 1)];
1225 + return $items[rand(0, count($items) - 1)];
1229 1226 }
1230 1227 function qcld_wb_chatbot_func_str_replace($messages = array()){
1231 1228 $refined_mesgses = array();
1232 1229 foreach ($messages as $message) {
@@ -1241,10 +1238,10 @@
1241 1238 // First check the nonce, if it fails the function will break
1242 1239 check_ajax_referer('wpwbot-order-nonce', 'security');
1243 1240 // Nonce is checked, get the POST data and sign user on
1244 1241 $info = array();
1245 - $info['user_login'] = trim(sanitize_text_field(wp_unslash($_POST['user_name'])));
1246 - $info['user_password'] = trim(sanitize_text_field(wp_unslash($_POST['user_pass'])));
1242 + $info['user_login'] = trim(sanitize_text_field($_POST['user_name']));
1243 + $info['user_password'] = trim(sanitize_text_field($_POST['user_pass']));
1247 1244 $info['remember'] = true;
1248 1245 $user_signon = wp_signon($info, false);
1249 1246 $response = array();
1250 1247 if (is_wp_error($user_signon)) {
@@ -1284,12 +1281,12 @@
1284 1281 if ($response['order_num'] > 0) {
1285 1282 $response['message'] .= wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_order_found'))));
1286 1283 $order_html .= '<div class="wp-chatbot-orders-container">
1287 1284 <div class="wp-chatbot-orders-header">
1288 - <div class="order-id">' . __('ID', 'chatbot') . '</div>
1289 - <div class="order-date">' . __('Date', 'chatbot') . ' </div>
1290 - <div class="order-items">' . __('Items', 'chatbot') . '</div>
1291 - <div class="order-status">' . __('Status', 'chatbot') . '</div>
1285 + <div class="order-id">' . __('ID', 'wpchatbot') . '</div>
1286 + <div class="order-date">' . __('Date', 'wpchatbot') . ' </div>
1287 + <div class="order-items">' . __('Items', 'wpchatbot') . '</div>
1288 + <div class="order-status">' . __('Status', 'wpchatbot') . '</div>
1292 1289 </div>';
1293 1290 foreach ($customer_orders as $order) {
1294 1291 //Formatting order summery
1295 1292 if (isset($_COOKIE['from_app']) && $_COOKIE['from_app'] == 'yes') {
@@ -1300,9 +1297,9 @@
1300 1297 $order_url = '<a href="' . get_url(get_permalink(get_option('wpcommerce_myaccount_page_id')) . '/view-order/' . $order->ID) . '" target="_blank" >' . $order->ID . '</a>';
1301 1298 }
1302 1299 $order_html .= '<div class="wp-chatbot-orders-single">
1303 1300 <div class="order-id"> ' . $order_url . '</div>
1304 - <div class="order-date"> <p>' . gmdate("m/d/Y", strtotime($order->post_date)) . '</p> </div>
1301 + <div class="order-date"> <p>' . date("m/d/Y", strtotime($order->post_date)) . '</p> </div>
1305 1302 <div class="order-items">';
1306 1303 $singleOrder = new WC_Order($order->ID);
1307 1304 $items = $singleOrder->get_items();
1308 1305 foreach ($items as $item) {
@@ -1402,9 +1399,9 @@
1402 1399 $html .= get_the_post_thumbnail(get_the_ID(), 'shop_catalog') . '
1403 1400 <div class="wp-chatbot-product-summary">
1404 1401 <div class="wp-chatbot-product-table">
1405 1402 <div class="wp-chatbot-product-table-cell">
1406 - <h3 class="wp-chatbot-product-title">' . esc_html($product->post->post_title) . '</h3>
1403 + <h3 class="wp-chatbot-product-title">' . $product->post->post_title . '</h3>
1407 1404 <div class="price">' . $product->get_price_html() . '</div>';
1408 1405 $html .= ' </div>
1409 1406 </div>
1410 1407 </div></a>
@@ -1473,9 +1470,9 @@
1473 1470 $html .= get_the_post_thumbnail(get_the_ID(), 'shop_catalog') . '
1474 1471 <div class="wp-chatbot-product-summary">
1475 1472 <div class="wp-chatbot-product-table">
1476 1473 <div class="wp-chatbot-product-table-cell">
1477 - <h3 class="wp-chatbot-product-title">' . esc_html($product->post->post_title) . '</h3>
1474 + <h3 class="wp-chatbot-product-title">' . $product->post->post_title . '</h3>
1478 1475 <div class="price">' . $product->get_price_html() . '</div>';
1479 1476 $html .= ' </div>
1480 1477 </div>
1481 1478 </div></a>
@@ -1485,9 +1482,9 @@
1485 1482 wp_reset_postdata();
1486 1483 $html .= '</ul></div>';
1487 1484 } else {
1488 1485 $html .= '<div class="wp-chatbot-products-area">';
1489 - $html .= '<p style="text-align: center">' . __('You have no products', 'chatbot') . ' !';
1486 + $html .= '<p style="text-align: center">' . __('You have no products', 'wpchatbot') . ' !';
1490 1487 $html .= '</div>';
1491 1488 }
1492 1489 return $html;
1493 1490 }
@@ -1649,12 +1646,11 @@
1649 1646 //Updating the cart items.
1650 1647 add_action('wp_ajax_qcld_wb_chatbot_update_cart_item_number', 'qcld_wb_chatbot_update_cart_item_number');
1651 1648 add_action('wp_ajax_nopriv_qcld_wb_chatbot_update_cart_item_number', 'qcld_wb_chatbot_update_cart_item_number');
1652 1649 function qcld_wb_chatbot_update_cart_item_number(){
1653 - check_ajax_referer( 'wp_chatbot', 'nonce' );
1654 1650 //getting cart items n
1655 - $cart_item_key = sanitize_text_field(wp_unslash($_POST['cart_item_key']));
1656 - $qnty = sanitize_text_field(wp_unslash($_POST['qnty']));
1651 + $cart_item_key = sanitize_text_field($_POST['cart_item_key']);
1652 + $qnty = sanitize_text_field($_POST['qnty']);
1657 1653 global $wpcommerce;
1658 1654 $result = $wpcommerce->cart->set_quantity($cart_item_key, $qnty);
1659 1655 wp_send_json($result);
1660 1656 }
@@ -1661,11 +1657,10 @@
1661 1657 //Show item after removing from cart page.
1662 1658 add_action('wp_ajax_qcld_wb_chatbot_cart_item_remove', 'qcld_wb_chatbot_cart_item_remove');
1663 1659 add_action('wp_ajax_nopriv_qcld_wb_chatbot_cart_item_remove', 'qcld_wb_chatbot_cart_item_remove');
1664 1660 function qcld_wb_chatbot_cart_item_remove(){
1665 - check_ajax_referer( 'wp_chatbot', 'nonce' );
1666 1661 //getting cart items n
1667 - $cart_item_key = sanitize_text_field(wp_unslash($_POST['cart_item']));
1662 + $cart_item_key = sanitize_text_field($_POST['cart_item']);
1668 1663 global $wpcommerce;
1669 1664 $result = $wpcommerce->cart->remove_cart_item($cart_item_key);
1670 1665 wp_send_json($result);
1671 1666 }
@@ -1702,9 +1697,9 @@
1702 1697 $response = array('status' => $status, 'html' => $html);
1703 1698 wp_send_json($response);
1704 1699 }
1705 1700 //_dynamic_intent
1706 -function qcld_dynamic_intent(){
1701 +function qc_dynamic_intent(){
1707 1702 global $wpdb;
1708 1703 $intents = array();
1709 1704
1710 1705 $ai_df = get_option('enable_wp_chatbot_dailogflow');
@@ -1721,10 +1716,9 @@
1721 1716
1722 1717 if(class_exists('Qcformbuilder_Forms_Admin')){
1723 1718
1724 1719
1725 - $results = $wpdb->get_results($wpdb->prepare("SELECT * FROM ". $wpdb->prefix."wfb_forms WHERE type= %s",'primary')); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1726 -
1720 + $results = $wpdb->get_results("SELECT * FROM ". $wpdb->prefix."wfb_forms where 1 and type='primary'");
1727 1721 if(!empty($results)){
1728 1722
1729 1723 foreach($results as $result){
1730 1724 $form = maybe_unserialize($result->config);
@@ -1748,10 +1742,10 @@
1748 1742 // function qcld_wb_chatbot_checkout_user_login(){
1749 1743 // // Nonce is checked, get the POST data and sign user on
1750 1744 // $info = array();
1751 1745 // //$info['nonce'] = $_POST['nonce_val'];
1752 -// $info['user_login'] = trim(sanitize_text_field(wp_unslash($_POST['user_name'])));
1753 -// $info['user_password'] = trim(sanitize_text_field(wp_unslash($_POST['user_pass'])));
1746 +// $info['user_login'] = trim(sanitize_text_field($_POST['user_name']));
1747 +// $info['user_password'] = trim(sanitize_text_field($_POST['user_pass']));
1754 1748 // $info['remember'] = true;
1755 1749 // $user_signon = wp_signon($info, false);
1756 1750 // // $response=$info;
1757 1751 // $response = array();
@@ -1792,16 +1786,15 @@
1792 1786 add_action('init', 'wp_chatbot_create_app_checkout_thankyou_page');
1793 1787 function wp_chatbot_create_app_checkout_thankyou_page(){
1794 1788 if (get_option('wp_chatbot_app_pages') == 1) {
1795 1789 //Mobile App page create
1796 - $existing_app = new WP_Query( array( 'post_type' => 'page', 'name' => 'wpwbot-mobile-app', 'post_status' => 'publish', 'posts_per_page' => 1 ) );
1797 - if ( ! $existing_app->have_posts() ) {
1790 + if (get_page_by_title('wpwBot Mobile App') == NULL) {
1798 1791 //post status and options
1799 1792 $app_page = array(
1800 1793 'comment_status' => 'closed',
1801 1794 'ping_status' => 'closed',
1802 1795 'post_author' => get_current_user_id(),
1803 - 'post_date' => gmdate('Y-m-d H:i:s'),
1796 + 'post_date' => date('Y-m-d H:i:s'),
1804 1797 'post_status' => 'publish',
1805 1798 'post_title' => 'wpwBot Mobile App',
1806 1799 'post_name' => 'wpwbot-mobile-app',
1807 1800 'post_type' => 'page',
@@ -1811,16 +1804,15 @@
1811 1804 //save the id in the database
1812 1805 update_option('wp_chatbot_app_checkout', $wpwbot_app);
1813 1806 }
1814 1807 //App checkout page create
1815 - $existing_checkout = new WP_Query( array( 'post_type' => 'page', 'name' => 'wpwbot-app-checkout', 'post_status' => 'publish', 'posts_per_page' => 1 ) );
1816 - if ( ! $existing_checkout->have_posts() ) {
1808 + if (get_page_by_title('wpwBot App Checkout') == NULL) {
1817 1809 //post status and options
1818 1810 $checkout_page = array(
1819 1811 'comment_status' => 'closed',
1820 1812 'ping_status' => 'closed',
1821 1813 'post_author' => get_current_user_id(),
1822 - 'post_date' => gmdate('Y-m-d H:i:s'),
1814 + 'post_date' => date('Y-m-d H:i:s'),
1823 1815 'post_status' => 'publish',
1824 1816 'post_title' => 'wpwBot App Checkout',
1825 1817 'post_name' => 'wpwbot-app-checkout',
1826 1818 'post_type' => 'page',
@@ -1830,16 +1822,15 @@
1830 1822 //save the id in the database
1831 1823 update_option('wp_chatbot_app_checkout', $app_checkout);
1832 1824 }
1833 1825 //App Order thank you page create
1834 - $existing_thankyou = new WP_Query( array( 'post_type' => 'page', 'name' => 'wpwbot-app-order-thankyou', 'post_status' => 'publish', 'posts_per_page' => 1 ) );
1835 - if ( ! $existing_thankyou->have_posts() ) {
1826 + if (get_page_by_title('wpwBot App Order Thank You') == NULL) {
1836 1827 //post status and options
1837 1828 $thankyou_page = array(
1838 1829 'comment_status' => 'closed',
1839 1830 'ping_status' => 'closed',
1840 1831 'post_author' => get_current_user_id(),
1841 - 'post_date' => gmdate('Y-m-d H:i:s'),
1832 + 'post_date' => date('Y-m-d H:i:s'),
1842 1833 'post_status' => 'publish',
1843 1834 'post_title' => 'wpwBot App Order Thank You',
1844 1835 'post_name' => 'wpwbot-app-order-thankyou',
1845 1836 'post_type' => 'page',
@@ -1850,9 +1841,9 @@
1850 1841 update_option('wp_chatbot_app_order_thankyou', $app_order_thankyou);
1851 1842 }
1852 1843 }
1853 1844 //Keep tracking from App by cookies
1854 - if ( isset( $_GET['from'] ) && sanitize_text_field( wp_unslash( $_GET['from'] ) ) === 'app' ) { // phpcs:ignore WordPress.Security.NonceVerification
1845 + if (isset($_GET['from']) && $_GET['from'] == 'app') {
1855 1846 if (!isset($_COOKIE['from_app'])) {
1856 1847 setcookie('from_app', 'yes', (time() + 3600), '/');
1857 1848 }
1858 1849 }
@@ -1866,9 +1857,9 @@
1866 1857 global $wp;
1867 1858 if (is_checkout() && !empty($wp->query_vars['order-received'])) {
1868 1859 $thanks_page_id = get_option('wp_chatbot_app_order_thankyou');
1869 1860 $thanks_parmanlink = esc_url(get_permalink($thanks_page_id));
1870 - wp_safe_redirect($thanks_parmanlink . '?order_id=' . $order_get_id);
1861 + wp_redirect($thanks_parmanlink . '?order_id=' . $order_get_id);
1871 1862 exit;
1872 1863 }
1873 1864 } else {
1874 1865 remove_action('wpcommerce_thankyou', 'qcld_wb_chatbot__redirect_after_purchase');
@@ -1876,12 +1867,9 @@
1876 1867 }
1877 1868 }
1878 1869
1879 1870 function qcld_choose_random($array){
1880 - if (is_array($array) && !empty($array)) {
1881 - return $array[array_rand($array)];
1882 - }
1883 - return $array;
1871 + return $array[array_rand($array)];
1884 1872 }
1885 1873
1886 1874 //User session count
1887 1875 add_action('wp_ajax_qcld_wb_chatbot_session_count', 'qcld_wb_chatbot_session_count');
@@ -1887,9 +1875,8 @@
1887 1875 add_action('wp_ajax_qcld_wb_chatbot_session_count', 'qcld_wb_chatbot_session_count');
1888 1876 add_action('wp_ajax_nopriv_qcld_wb_chatbot_session_count', 'qcld_wb_chatbot_session_count');
1889 1877 function qcld_wb_chatbot_session_count(){
1890 1878 // Nonce is checked, get the POST data and sign user on
1891 - check_ajax_referer( 'wp_chatbot', 'nonce' );
1892 1879 global $wpdb;
1893 1880 $wpdb->show_errors = true;
1894 1881 $tableuser = $wpdb->prefix.'wpbot_sessions';
1895 1882 $response = array();
@@ -1894,12 +1881,11 @@
1894 1881 $tableuser = $wpdb->prefix.'wpbot_sessions';
1895 1882 $response = array();
1896 1883
1897 1884
1898 - $session_exists = $wpdb->get_row($wpdb->prepare("select * from {$tableuser} where 1 and id = %d",1)); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, PluginCheck.Security.DirectDB.UnescapedDBParameter
1899 -
1885 + $session_exists = $wpdb->get_row("select * from $tableuser where 1 and id = '1'");
1900 1886 if(empty($session_exists)){
1901 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
1887 + $wpdb->insert(
1902 1888 $tableuser,
1903 1889 array(
1904 1890 'session' => 1,
1905 1891 )
@@ -1906,10 +1892,9 @@
1906 1892 );
1907 1893 }else{
1908 1894
1909 1895 $session_id = $session_exists->id;
1910 -
1911 - $wpdb->update( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1896 + $wpdb->update(
1912 1897 $tableuser,
1913 1898 array(
1914 1899 'session'=>($session_exists->session+1),
1915 1900 ),
@@ -1918,9 +1903,8 @@
1918 1903 '%d',
1919 1904 ),
1920 1905 array('%d')
1921 1906 );
1922 -
1923 1907 }
1924 1908
1925 1909 wp_send_json($response);
1926 1910 }
@@ -1927,9 +1911,9 @@
1927 1911
1928 1912 /* WPBot Chat History Addon check */
1929 1913 function qcld_wpbot_is_active_chat_history(){
1930 1914
1931 - if(function_exists('qcwp_chat_session_menu_fnc') || function_exists('qcwp_chat_session_menu_fnc_free') || function_exists( 'qcpdcs_chat_session_menu_fnc' ) ){
1915 + if(function_exists('qcwp_chat_session_menu_fnc') || function_exists( 'qcpdcs_chat_session_menu_fnc' ) ){
1932 1916 return 1;
1933 1917 }else{
1934 1918 return 0;
1935 1919 }
@@ -1935,83 +1919,23 @@
1935 1919 }
1936 1920
1937 1921 }
1938 1922
1939 -/**
1940 - * Safely sanitize chatbot conversation input.
1941 - *
1942 - * SECURITY FIX (CVE WPBot Stored XSS ≤ 8.6.9):
1943 - * The previous order was: wp_kses() → html_entity_decode() → htmlspecialchars().
1944 - * An attacker could submit entity-encoded payloads (&lt;img onerror=...&gt;) that
1945 - * bypassed wp_kses (which saw inert text), were then decoded back into live markup
1946 - * by html_entity_decode(), and survived into storage and the admin UI.
1947 - *
1948 - * Correct order: html_entity_decode() FIRST → wp_kses() → htmlspecialchars().
1949 - * wp_kses() now sees the real decoded markup and strips forbidden tags/attributes.
1950 - *
1951 - * @param string $data Raw conversation string (already wp_unslash'd by caller).
1952 - * @return string Sanitized, entity-encoded string safe for DB storage.
1953 - */
1954 -function qcld_wpbot_input_validation( $data ) {
1955 - // 1. Decode any entity-encoded HTML so wp_kses sees the real markup.
1956 - $data = html_entity_decode( $data, ENT_QUOTES | ENT_HTML5, 'UTF-8' );
1957 - $data = trim( $data );
1958 - $data = stripslashes( $data );
1959 - // 2. Sanitize with a strict allowlist — NOW operating on decoded markup.
1960 - $data = wp_kses( $data, wpbot_get_safe_conversation_tags() );
1961 - // 3. Re-encode for safe DB storage; admin.js decodes for rendering.
1962 - $data = htmlspecialchars( $data, ENT_QUOTES | ENT_HTML5, 'UTF-8' );
1923 +function qc_wpbot_input_validation( $data ) {
1924 + $data = html_entity_decode($data);
1925 + $data = trim($data);
1926 + $data = stripslashes($data);
1927 + $data = htmlspecialchars($data);
1963 1928 return $data;
1964 1929 }
1965 -
1966 -/**
1967 - * Returns the strict HTML allowlist for chatbot conversation content.
1968 - *
1969 - * Critically: no event-handler attributes (onerror, onclick, onload, etc.) are
1970 - * allowed — wp_kses strips any attribute not explicitly listed here.
1971 - * 'img' is intentionally omitted; bot responses that include images should use
1972 - * safe URLs only and can be re-added with only 'src', 'alt', 'class' if needed.
1973 - *
1974 - * @return array<string, array<string, bool>>
1975 - */
1976 -function wpbot_get_safe_conversation_tags() {
1977 - return array(
1978 - 'ul' => array( 'class' => true ),
1979 - 'ol' => array( 'class' => true ),
1980 - 'li' => array( 'class' => true, 'id' => true ),
1981 - 'div' => array( 'class' => true, 'id' => true ),
1982 - 'span' => array( 'class' => true, 'id' => true ),
1983 - 'p' => array( 'class' => true ),
1984 - 'br' => array(),
1985 - 'strong' => array(),
1986 - 'em' => array(),
1987 - 'b' => array(),
1988 - 'i' => array(),
1989 - 'a' => array(
1990 - 'href' => true,
1991 - 'target' => true,
1992 - 'rel' => true,
1993 - 'class' => true,
1994 - ),
1995 - // 'img' intentionally excluded — prevents onerror/onload injection.
1996 - // Add back with only 'src','alt','class' if bot image responses are needed.
1997 - );
1998 -}
1999 -add_action('wp_ajax_qcld_small_talk_import', 'qcld_small_talk_import');
2000 -function qcld_small_talk_import(){
2001 - if ( ! current_user_can( 'manage_options' ) ) {
2002 - wp_die();
2003 - }
1930 +add_action('wp_ajax_small_talk_import', 'small_talk_import');
1931 +function small_talk_import(){
2004 1932 global $wpdb;
2005 -
2006 1933 $table = $wpdb->prefix.'wpbot_response';
2007 -
2008 1934 $csvFile = file(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . 'small_talk.csv');
2009 -
2010 1935 foreach ($csvFile as $line) {
2011 1936 $line = str_getcsv($line, ',', '"');
2012 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
2013 - $table, array(
1937 + $wpdb->insert($table, array(
2014 1938 'query' => $line[0],
2015 1939 'keyword' => $line[1],
2016 1940 'response' => $line[2],
2017 1941 'category'=> $line[3],
@@ -2018,16 +1942,12 @@
2018 1942 'intent'=> '',
2019 1943 //'lang'=> 'en_US',
2020 1944 ));
2021 1945 }
2022 -
2023 1946 $table2 = $wpdb->prefix.'wpbot_response_category';
2024 -
2025 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
2026 - $table2, array(
1947 + $wpdb->insert($table2, array(
2027 1948 'name' => 'smalltalk',
2028 1949 ));
2029 -
2030 1950 update_option( 'qcld_small_talk_imported', 'yes' );
2031 1951
2032 1952 }
2033 1953 function sanitize_array( &$array ) {
@@ -2034,47 +1954,12 @@
2034 1954 if (!empty($array)) {
2035 1955 foreach ($array as &$value) {
2036 1956 if( !is_array($value) )
2037 1957 // sanitize if value is not an array
2038 - $value = sanitize_text_field( esc_html($value) );
1958 + $value = sanitize_text_field( $value );
2039 1959 else
2040 1960 // go inside this function again
2041 - sanitize_array(esc_html($value));
1961 + $this->sanitize_array($value);
2042 1962 }
2043 1963 }
2044 1964 return $array;
2045 -}
2046 -function qcld_wpbot_meta_tags() {
2047 - echo '<!-- "This site uses ChatBot for WordPress - WPBot from https://www.wpbot.pro/" -->';
2048 -}
2049 -add_action('wp_footer', 'qcld_wpbot_meta_tags', 100);
2050 -
2051 -if ( ! function_exists( 'qcld_change_language_from_center' ) ) {
2052 - add_action( 'wp_ajax_qcld_change_language_from_center', 'qcld_change_language_from_center' );
2053 - add_action( 'wp_ajax_nopriv_qcld_change_language_from_center', 'qcld_change_language_from_center' );
2054 - function qcld_change_language_from_center() {
2055 - if ( ! current_user_can( 'manage_options' ) ) {
2056 - wp_send_json_error( array( 'message' => 'Unauthorized.' ) );
2057 - }
2058 - $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( wp_unslash( $_POST['nonce'] ) ) : '';
2059 - if ( ! wp_verify_nonce( $nonce, 'wp_chatbot' ) ) {
2060 - wp_send_json_error( array( 'message' => 'Invalid nonce.' ) );
2061 - }
2062 - $plugin_path = plugin_dir_path( __FILE__ );
2063 - include $plugin_path . 'includes/admin/settings-fields.php';
2064 - $json_file_path = $plugin_path . 'includes/language-center.json';
2065 -
2066 - $json_string = file_get_contents( $json_file_path );
2067 - if ( isset( $_POST['language'] ) ) {
2068 - $language = sanitize_text_field( wp_unslash( $_POST['language'] ) );
2069 - $language_array= json_decode($json_string)->$language;
2070 - update_option( 'wp_chatbot_language_center_language', $language );
2071 - wp_send_json_success( array( 'message' => true, 'data' => $language_array, 'language' => $language ) );
2072 - } else {
2073 - wp_send_json_error( array( 'message' => 'Language not specified.' ) );
2074 -
2075 - }
2076 - }
2077 -}
2078 -
2079 -// AI Actions Chat Preview
2080 -
1965 +}