PluginProbe
WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services / 5.4.2
WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services v5.4.2
8.7.7 8.7.6 8.7.5 8.7.4 8.7.3 8.7.2 8.7.1 8.7.0 8.6.9 8.6.8 8.6.7 8.6.6 8.6.5 8.6.4 8.6.2 8.6.1 8.6.0 8.5.9 8.5.8 8.5.7 8.5.6 8.5.5 8.5.4 8.5.3 8.5.2 All 533 releases
← All changes | functions.php +307 -394 8.7.55.4.2 View file →
@@ -3,48 +3,11 @@
3 3 * @param $type
4 4 * Display wpwBot Icon ball
5 5 */
6 6 if (!defined('ABSPATH')) exit; // Exit if accessed directly
7 -
8 -
9 -function qcld_custom_search_form( $form ) {
10 - // Add a hidden input to limit search to 'product' post type
11 - if (get_option('wp_chatbot_agent_image') == "custom-agent.png") {
12 - $wp_chatbot_custom_agent_path = get_option('wp_chatbot_custom_agent_path');
13 - } else if (get_option('wp_chatbot_agent_image') != "custom-agent.png") {
14 - $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_agent_image');
15 - } else {
16 - $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . 'custom-agent.png';
17 - }
18 - $hidden_field = '<a class="wp-chatbot qc_wpbot_chat_link" id="wp-chatbot-search-btn" data-search-type="product" data-search-term="" style="max-height: 50px; margin-left: 10px;padding: 0 !important;position: absolute;top: -9px;right: -60px;"><img src="'. esc_url($wp_chatbot_custom_agent_path) .'" alt=""></a>';
19 - $block_content = str_replace( '</form>', $hidden_field . '</form>', $form );
20 - return $block_content;
21 -}
22 -if(get_option('wpbot_enable_on_search') == 1 && (get_option('disable_floating_button') != '1') && get_option('disable_wp_chatbot') != 1 ){
23 - add_filter( 'get_search_form', 'qcld_custom_search_form' );
24 - add_filter( 'render_block_core/search', 'qcld_modify_gutenberg_search_block', 10, 2 );
25 -}
26 -
27 -
28 -function qcld_modify_gutenberg_search_block( $block_content, $block ) {
29 - // Add a hidden input to limit search to 'product' post type
30 - if (get_option('wp_chatbot_agent_image') == "custom-agent.png") {
31 - $wp_chatbot_custom_agent_path = get_option('wp_chatbot_custom_agent_path');
32 - } else if (get_option('wp_chatbot_agent_image') != "custom-agent.png") {
33 - $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_agent_image');
34 - } else {
35 - $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . 'custom-agent.png';
36 - }
37 - $hidden_field = '<button type="button" class="wp-chatbot qc_wpbot_chat_link" id="wp-chatbot-search-btn" data-search-type="product" data-search-term="" style="max-height: 50px; margin-left: 10px;padding: 0 !important"><img src="'. esc_url($wp_chatbot_custom_agent_path) .'" alt=""></button>';
38 - // Inject the hidden field before the closing </form> tag
39 - $block_content = str_replace( '</div></form>', $hidden_field . '</div></form>', $block_content );
40 - return $block_content;
41 -}
42 -if(get_option('disable_floating_button') != '1'){
43 - add_action('wp_footer', 'wp_chatbot_load_footer_html');
44 -}
45 -add_action( 'admin_footer', 'qcld_style_for_hide_iframe');
46 -function qcld_style_for_hide_iframe(){
7 +add_action('wp_footer', 'wp_chatbot_load_footer_html');
8 +add_action( 'admin_footer', 'qc_style_for_hide_iframe');
9 +function qc_style_for_hide_iframe(){
47 10 ?>
48 11 <script>
49 12 jQuery( document ).ready(function() {
50 13 setInterval(function(){
@@ -58,62 +21,8 @@
58 21 });
59 22 </script>
60 23 <?php
61 24 }
62 -/**
63 - * Extract a YouTube video ID from common URL formats.
64 - *
65 - * @param string $url YouTube watch, embed, short, or youtu.be URL.
66 - * @return string Video ID or empty string.
67 - */
68 -if ( ! function_exists( 'qcld_wpbot_extract_youtube_id' ) ) {
69 - function qcld_wpbot_extract_youtube_id( $url ) {
70 - $url = trim( (string) $url );
71 - if ( $url === '' ) {
72 - return '';
73 - }
74 -
75 - if ( preg_match( '/(?:youtube\.com\/(?:embed\/|shorts\/|live\/|watch\?(?:.*&)?v=)|youtu\.be\/)([A-Za-z0-9_-]{11})/', $url, $matches ) ) {
76 - return $matches[1];
77 - }
78 -
79 - $path = (string) wp_parse_url( $url, PHP_URL_PATH );
80 - $base = basename( $path );
81 - if ( preg_match( '/^[A-Za-z0-9_-]{11}$/', $base ) ) {
82 - return $base;
83 - }
84 -
85 - return '';
86 - }
87 -}
88 -if ( ! function_exists( 'qcld_wpbot_youtube_icon_embed_src' ) ) {
89 - function qcld_wpbot_youtube_icon_embed_src( $url ) {
90 - $video_id = qcld_wpbot_extract_youtube_id( $url );
91 - if ( $video_id === '' ) {
92 - return '';
93 - }
94 -
95 - return add_query_arg(
96 - array(
97 - 'autoplay' => '1',
98 - 'mute' => '1',
99 - 'loop' => '1',
100 - 'playlist' => $video_id,
101 - 'controls' => '0',
102 - 'showinfo' => '0',
103 - 'rel' => '0',
104 - 'fs' => '0',
105 - 'iv_load_policy' => '3',
106 - 'cc_load_policy' => '0',
107 - 'disablekb' => '1',
108 - 'playsinline' => '1',
109 - 'modestbranding' => '1',
110 - 'color' => 'white',
111 - ),
112 - 'https://www.youtube.com/embed/' . rawurlencode( $video_id )
113 - );
114 - }
115 -}
116 25 function wp_chatbot_load_footer_html(){
117 26 if ( get_option('disable_wp_chatbot') != 1 && wp_chatbot_load_controlling() === true) {
118 27
119 28 ?>
@@ -118,10 +27,11 @@
118 27
119 28 ?>
120 29 <style>
121 30 <?php if(get_option('wp_chatbot_custom_css')!="") {
122 -
123 - echo wp_strip_all_tags( get_option('wp_chatbot_custom_css') );// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
31 + //Sanitization to be checked
32 + // phpcs:ignore
33 + echo sanitize_text_field(get_option('wp_chatbot_custom_css'));
124 34 }
125 35 ?>
126 36 </style>
127 37
@@ -133,27 +43,10 @@
133 43 }
134 44 ?>
135 45 <style>
136 46 .wp-chatbot-container {
137 - background-color: #eceef3 !important;
138 47 background-image: url(<?php echo esc_url($qcld_wb_chatbot_board_bg_path); ?>) !important;
139 - background-size: cover !important;
140 - background-position: center !important;
141 - background-repeat: no-repeat !important;
142 48 }
143 - .wp-chatbot-template-01 #wp-chatbot-board-container,
144 - .wp-chatbot-template-01 .wp-chatbot-board-container {
145 - background-color: #eceef3 !important;
146 - background-image: none !important;
147 - }
148 - .wp-chatbot-template-01 #wp-chatbot-board-container::before,
149 - .wp-chatbot-template-01 .wp-chatbot-board-container::before {
150 - background-color: #eceef3 !important;
151 - background-image: url(<?php echo esc_url($qcld_wb_chatbot_board_bg_path); ?>) !important;
152 - background-size: cover !important;
153 - background-position: center !important;
154 - background-repeat: no-repeat !important;
155 - }
156 49 </style>
157 50 <?php }
158 51 $wp_chatbot_enable_rtl = "";
159 52 if (get_option('enable_wp_chatbot_rtl') == '1') {
@@ -163,33 +56,33 @@
163 56 // if (get_option('enable_wp_chatbot_mobile_full_screen')==1) {
164 57 $wp_chatbot_enable_mobile_screen .= "wp-chatbot-mobile-full-screen";
165 58 // }
166 59 ?>
167 - <div id="wp-chatbot-chat-container" class="<?php echo esc_attr($wp_chatbot_enable_rtl .' '.$wp_chatbot_enable_mobile_screen); ?>" style="<?php if(get_option('disable_floating_button') == '1'){ echo 'display:none';} ?>">
60 + <div id="wp-chatbot-chat-container" class="<?php echo esc_attr($wp_chatbot_enable_rtl .' '.$wp_chatbot_enable_mobile_screen); ?>">
168 61 <div id="wp-chatbot-integration-container">
169 62 <div class="wp-chatbot-integration-button-container">
170 63 <?php if (get_option('enable_wp_chatbot_skype_floating_icon') == 1) { ?>
171 64 <a href="skype:<?php echo esc_attr(get_option('enable_wp_chatbot_skype_id')); ?>?chat"><span
172 - class="inetegration-skype-btn" title="<?php esc_attr_e('Skype', 'chatbot'); ?>"> </span></a>
65 + class="inetegration-skype-btn" title="<?php esc_attr_e('Skype', 'wpchatbot'); ?>"> </span></a>
173 66 <?php } ?>
174 67 <?php if (get_option('enable_wp_chatbot_floating_whats') == 1) { ?>
175 68 <a href="<?php echo esc_url('https://api.whatsapp.com/send?phone=' . get_option('qlcd_wp_chatbot_whats_num')); ?>"
176 69 target="_blank"><span class="intergration-whats"
177 - title="<?php esc_html_e('WhatsApp', 'chatbot'); ?>"></span></a>
70 + title="<?php esc_html_e('WhatsApp', 'wpchatbot'); ?>"></span></a>
178 71 <?php } ?>
179 72 <?php if (get_option('enable_wp_chatbot_floating_viber') == 1) { ?>
180 73 <a href="<?php echo esc_url('https://live.viber.com/#/' . get_option('qlcd_wp_chatbot_viber_acc')); ?>"
181 74 target="_blank"><span class="intergration-viber"
182 - title="<?php esc_html_e('Viber', 'chatbot'); ?>"></span></a>
75 + title="<?php esc_html_e('Viber', 'wpchatbot'); ?>"></span></a>
183 76 <?php } ?>
184 77 <?php if (get_option('enable_wp_chatbot_floating_phone') == 1 && get_option('qlcd_wp_chatbot_phone') != "") { ?>
185 78 <a href="tel:<?php echo esc_attr(get_option('qlcd_wp_chatbot_phone')); ?>"><span
186 79 class="intergration-phone"
187 - title="<?php esc_html_e('Phone', 'chatbot'); ?>"> </span></a>
80 + title="<?php esc_html_e('Phone', 'wpchatbot'); ?>"> </span></a>
188 81 <?php } ?>
189 82 <?php if (get_option('enable_wp_chatbot_floating_link') == 1 && get_option('qlcd_wp_chatbot_weblink') != "") { ?>
190 83 <a href="<?php echo esc_url(get_option('qlcd_wp_chatbot_weblink')); ?>" target="_blank"><span
191 - class="intergration-weblink" title="<?php esc_html_e('Web Link', 'chatbot'); ?>"></span></a>
84 + class="intergration-weblink" title="<?php esc_html_e('Web Link', 'wpchatbot'); ?>"></span></a>
192 85 <?php } ?>
193 86 </div>
194 87 </div>
195 88 <?php
@@ -202,9 +95,9 @@
202 95 }
203 96 if (file_exists(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/template.php')) {
204 97 require_once(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/template.php');
205 98 } else {
206 - echo "<h2>" . esc_html__('No wpWBot Theme Found!', 'chatbot') . "</h2>";
99 + echo "<h2>" . esc_html__('No wpWBot Theme Found!', 'wpchatbot') . "</h2>";
207 100 }
208 101 ?>
209 102 <?php
210 103 if (get_option('disable_wp_chatbot_notification') != 1) {
@@ -211,9 +104,9 @@
211 104 ?>
212 105 <div id="wp-chatbot-notification-container" class="wp-chatbot-notification-container">
213 106 <div class="wp-chatbot-notification-controller">
214 107 <span class="wp-chatbot-notification-close">
215 - <?php esc_html_e('X', 'chatbot'); ?>
108 + <?php esc_html_e('X', 'wpchatbot'); ?>
216 109 </span>
217 110 </div>
218 111 <?php
219 112 $testingTip="";
@@ -226,9 +119,9 @@
226 119 }
227 120 ?>
228 121 <div class="wp-chatbot-notification-agent-profile">
229 122 <div class="wp-chatbot-notification-widget-avatar" ><img
230 - src="<?php echo esc_url($wp_chatbot_custom_agent_path); ?>" alt=""></div>
123 + src="<?php echo esc_attr($wp_chatbot_custom_agent_path); ?>" alt=""></div>
231 124 <div class="wp-chatbot-notification-welcome"><?php echo wp_kses_post(wpb_randmom_message_handle(maybe_unserialize(get_option('qlcd_wp_chatbot_welcome')))) . ' <strong>' . esc_html(get_option('qlcd_wp_chatbot_host')) . '</strong>'; ?></div>
232 125 </div>
233 126 <?php
234 127 //update_option('qlcd_wp_chatbot_notifications','Welcome to WpBot');
@@ -251,72 +144,14 @@
251 144 $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_icon');
252 145 } else {
253 146 $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . 'custom.png';
254 147 }
255 - $_wpbot_icon_video = get_option('wp_chatbot_icon_video', '');
256 - $_wpbot_video_is_youtube = ( strpos( $_wpbot_icon_video, 'youtube.com' ) !== false || strpos( $_wpbot_icon_video, 'youtu.be' ) !== false );
257 - $_wpbot_youtube_embed_src = $_wpbot_video_is_youtube ? qcld_wpbot_youtube_icon_embed_src( $_wpbot_icon_video ) : '';
258 - $_wpbot_video_delay_ms = absint( get_option( 'wp_chatbot_icon_video_delay', 0 ) ) * 1000;
259 -
260 - $wp_chatbot_ball_is_youtube = ($_wpbot_icon_video !== '' && (strpos($_wpbot_icon_video, 'youtube.com') !== false || strpos($_wpbot_icon_video, 'youtu.be') !== false));
261 - $wp_chatbot_ball_is_video = ($_wpbot_icon_video !== '' && !$wp_chatbot_ball_is_youtube);
262 - $wp_chatbot_ball_has_video = ($wp_chatbot_ball_is_youtube || $wp_chatbot_ball_is_video);
263 148 ?>
264 149 <img src="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>"
265 - alt="wpChatIcon" qcld_agent="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>"
266 - id="wp-chatbot-ball-icon-img"
267 - <?php if ($wp_chatbot_ball_has_video) { echo 'style="display:none;"'; } ?> >
268 - <?php if ( $_wpbot_icon_video !== '' ) : ?>
269 - <?php if ( $_wpbot_video_is_youtube && $_wpbot_youtube_embed_src !== '' ) : ?>
270 - <iframe class="wpbot-icon-video" src="<?php echo $_wpbot_video_delay_ms > 0 ? 'about:blank' : esc_url( $_wpbot_youtube_embed_src ); ?>" data-wpbot-yt-src="<?php echo esc_url( $_wpbot_youtube_embed_src ); ?>" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture"></iframe>
271 - <?php elseif ( ! $_wpbot_video_is_youtube ) : ?>
272 - <video class="wpbot-icon-video" src="<?php echo esc_url( $_wpbot_icon_video ); ?>" autoplay muted loop playsinline preload="auto"></video>
273 - <?php endif; ?>
274 - <?php endif; ?>
150 + alt="wpChatIcon" qcld_agent="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>" >
151 +
275 152 </div>
276 -
277 153 </div>
278 - <?php
279 - if ( $_wpbot_icon_video !== '' ) :
280 - ?>
281 - <script>
282 - (function(){
283 - var wpbotDelay = <?php echo (int) $_wpbot_video_delay_ms; ?>;
284 - function wpbotForcePlay(){
285 - var v = document.querySelector('#wp-chatbot-ball video.wpbot-icon-video');
286 - if( v ){
287 - v.muted = true;
288 - v.volume = 0;
289 - v.loop = true;
290 - var tries = 0, maxTries = 30;
291 - var timer = setInterval(function(){
292 - tries++;
293 - v.play().then(function(){ clearInterval(timer); }).catch(function(){});
294 - if( tries >= maxTries ) clearInterval(timer);
295 - }, 300);
296 - }
297 - var yt = document.querySelector('#wp-chatbot-ball iframe.wpbot-icon-video');
298 - if( yt ){
299 - var ytSrc = yt.getAttribute('data-wpbot-yt-src');
300 - if( ytSrc && ( !yt.getAttribute('src') || yt.getAttribute('src') === 'about:blank' || yt.getAttribute('src').indexOf('autoplay=1') === -1 ) ){
301 - yt.setAttribute('src', ytSrc);
302 - }
303 - }
304 - }
305 - function wpbotDelayedPlay(){
306 - setTimeout(wpbotForcePlay, wpbotDelay);
307 - }
308 - if( document.readyState === 'loading' ){
309 - document.addEventListener('DOMContentLoaded', wpbotDelayedPlay);
310 - } else {
311 - wpbotDelayedPlay();
312 - }
313 - window.addEventListener('load', function(){
314 - setTimeout(wpbotForcePlay, wpbotDelay);
315 - });
316 - })();
317 - </script>
318 - <?php endif; ?>
319 154 <?php
320 155 $fb_app_id = get_option('qlcd_wp_chatbot_fb_app_id');
321 156 $fb_page_id = get_option('qlcd_wp_chatbot_fb_page_id');
322 157 $fb_mgs_color = get_option('qlcd_wp_chatbot_fb_color') != '' ? get_option('qlcd_wp_chatbot_fb_color') : '#0084ff';
@@ -359,11 +194,11 @@
359 194 </div>
360 195
361 196 <?php
362 197
363 - if ( get_transient( 'qcld_bot_clear_cache' ) ) {
198 + if ( get_transient( 'bot_clear_cache' ) ) {
364 199 echo '<script type="text/javascript">var wpbot_clear_cache = 1 </script>';
365 - delete_transient( 'qcld_bot_clear_cache' );
200 + delete_transient( 'bot_clear_cache' );
366 201 }
367 202
368 203 }else{
369 204 ?>
@@ -433,9 +268,9 @@
433 268 return $wp_chatbot_load;
434 269 }
435 270 //checking Devices
436 271 function wp_chatbot_is_mobile(){
437 - $useragent = isset( $_SERVER['HTTP_USER_AGENT'] ) ? $_SERVER['HTTP_USER_AGENT'] : '';
272 + $useragent = $_SERVER['HTTP_USER_AGENT'];
438 273 if (preg_match('/(android|bb\d+|meego).+mobile|avantgo|bada\/|blackberry|blazer|compal|elaine|fennec|hiptop|iemobile|ip(hone|od)|iris|kindle|lge |maemo|midp|mmp|netfront|opera m(ob|in)i|palm( os)?|phone|p(ixi|re)\/|plucker|pocket|psp|series(4|6)0|symbian|treo|up\.(browser|link)|vodafone|wap|windows (ce|phone)|xda|xiino/i', $useragent) || preg_match('/1207|6310|6590|3gso|4thp|50[1-6]i|770s|802s|a wa|abac|ac(er|oo|s\-)|ai(ko|rn)|al(av|ca|co)|amoi|an(ex|ny|yw)|aptu|ar(ch|go)|as(te|us)|attw|au(di|\-m|r |s )|avan|be(ck|ll|nq)|bi(lb|rd)|bl(ac|az)|br(e|v)w|bumb|bw\-(n|u)|c55\/|capi|ccwa|cdm\-|cell|chtm|cldc|cmd\-|co(mp|nd)|craw|da(it|ll|ng)|dbte|dc\-s|devi|dica|dmob|do(c|p)o|ds(12|\-d)|el(49|ai)|em(l2|ul)|er(ic|k0)|esl8|ez([4-7]0|os|wa|ze)|fetc|fly(\-|_)|g1 u|g560|gene|gf\-5|g\-mo|go(\.w|od)|gr(ad|un)|haie|hcit|hd\-(m|p|t)|hei\-|hi(pt|ta)|hp( i|ip)|hs\-c|ht(c(\-| |_|a|g|p|s|t)|tp)|hu(aw|tc)|i\-(20|go|ma)|i230|iac( |\-|\/)|ibro|idea|ig01|ikom|im1k|inno|ipaq|iris|ja(t|v)a|jbro|jemu|jigs|kddi|keji|kgt( |\/)|klon|kpt |kwc\-|kyo(c|k)|le(no|xi)|lg( g|\/(k|l|u)|50|54|\-[a-w])|libw|lynx|m1\-w|m3ga|m50\/|ma(te|ui|xo)|mc(01|21|ca)|m\-cr|me(rc|ri)|mi(o8|oa|ts)|mmef|mo(01|02|bi|de|do|t(\-| |o|v)|zz)|mt(50|p1|v )|mwbp|mywa|n10[0-2]|n20[2-3]|n30(0|2)|n50(0|2|5)|n7(0(0|1)|10)|ne((c|m)\-|on|tf|wf|wg|wt)|nok(6|i)|nzph|o2im|op(ti|wv)|oran|owg1|p800|pan(a|d|t)|pdxg|pg(13|\-([1-8]|c))|phil|pire|pl(ay|uc)|pn\-2|po(ck|rt|se)|prox|psio|pt\-g|qa\-a|qc(07|12|21|32|60|\-[2-7]|i\-)|qtek|r380|r600|raks|rim9|ro(ve|zo)|s55\/|sa(ge|ma|mm|ms|ny|va)|sc(01|h\-|oo|p\-)|sdk\/|se(c(\-|0|1)|47|mc|nd|ri)|sgh\-|shar|sie(\-|m)|sk\-0|sl(45|id)|sm(al|ar|b3|it|t5)|so(ft|ny)|sp(01|h\-|v\-|v )|sy(01|mb)|t2(18|50)|t6(00|10|18)|ta(gt|lk)|tcl\-|tdg\-|tel(i|m)|tim\-|t\-mo|to(pl|sh)|ts(70|m\-|m3|m5)|tx\-9|up(\.b|g1|si)|utst|v400|v750|veri|vi(rg|te)|vk(40|5[0-3]|\-v)|vm40|voda|vulc|vx(52|53|60|61|70|80|81|83|85|98)|w3c(\-| )|webc|whit|wi(g |nc|nw)|wmlb|wonu|x700|yas\-|your|zeto|zte\-/i', substr($useragent, 0, 4))) {
439 274 return true;
440 275 } else {
441 276 return false;
@@ -442,10 +277,10 @@
442 277 }
443 278 }
444 279 //Checking wpwbot opening hour
445 280 function wp_chatbot_check_opening_hours(){
446 - $curent_day=strtolower(gmdate('l',strtotime(current_time( 'mysql' ))));
447 - $current_time=gmdate('H:i',strtotime(current_time( 'mysql')));
281 + $curent_day=strtolower(date('l',strtotime(current_time( 'mysql' ))));
282 + $current_time=date('H:i',strtotime(current_time( 'mysql')));
448 283 $is_wpwbot_open =false;
449 284 if(get_option('wpwbot_hours')) {
450 285 $wpwbot_times = wp_kses_post(unserialize(get_option('wpwbot_hours')));
451 286 if (isset($wpwbot_times[$curent_day])) {
@@ -460,8 +295,198 @@
460 295 }
461 296 }
462 297 return $is_wpwbot_open;
463 298 }
299 +//wpwBot shortcode.
300 +add_shortcode('wpwbot', 'wp_chatbot_short_code');
301 +function wp_chatbot_short_code($atts = []){
302 + ob_start();
303 + wp_chatbot_shortcode_dom($atts);
304 + $content = ob_get_clean();
305 + return $content;
306 +}
307 +function wp_chatbot_shortcode_dom($atts){
308 + //Defaults & Set Parameters for shortcode
309 + extract(shortcode_atts(
310 + array(
311 + 'template' => '01',
312 + ), $atts
313 + ));
314 + ?>
315 + <style>
316 + <?php if(get_option('wp_chatbot_custom_css')!=""){
317 + //Sanitization to be checked
318 + // phpcs:ignore
319 + echo sanitize_text_field(get_option('wp_chatbot_custom_css'));
320 + } ?>
321 + </style>
322 + <?php if (get_option('qcld_wb_chatbot_change_bg') == 1) {
323 + if (get_option('qcld_wb_chatbot_board_bg_path') != "") {
324 + $qcld_wb_chatbot_board_bg_path = get_option('qcld_wb_chatbot_board_bg_path');
325 + } else {
326 + $qcld_wb_chatbot_board_bg_path = QCLD_wpCHATBOT_IMG_URL . 'background/background.png';
327 + }
328 + ?>
329 + <style>
330 + .wp-chatbot-container {
331 + background: url(<?php echo esc_url($qcld_wb_chatbot_board_bg_path) ;?>) no-repeat top right !important;
332 + }
333 + </style>
334 +<?php }
335 + $wp_chatbot_enable_rtl = "";
336 + if (get_option('enable_wp_chatbot_rtl')) {
337 + $wp_chatbot_enable_rtl .= "wp-chatbot-rtl";
338 + }
339 + ?>
340 + <div id="wp-chatbot-chat-container" class="<?php echo esc_attr($wp_chatbot_enable_rtl); ?>">
341 + <?php
342 + //Get wpcommerce cart
343 +
344 + $qcld_wb_chatbot_theme = 'template-' . $template;
345 + if (file_exists(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/style.css')) {
346 + wp_register_style('qcld-wp-chatbot-style', plugins_url(basename(plugin_dir_path(__FILE__)) . '/templates/' . $qcld_wb_chatbot_theme . '/style.css', basename(__FILE__)), '', QCLD_wpCHATBOT_VERSION, 'screen');
347 + wp_enqueue_style('qcld-wp-chatbot-style');
348 + }
349 + if (file_exists(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/template.php')) {
350 + require_once(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/template.php');
351 + } else {
352 + echo "<h2>" . esc_html__('No wpWBot Theme Found!', 'wpchatbot') . "</h2>";
353 + }
354 + ?>
355 + <?php if (get_option('disable_wp_chatbot') != 1): ?>
356 + <div id="wp-chatbot-notification-container" class="wp-chatbot-notification-container">
357 + <div class="wp-chatbot-notification-controller"> <span class="wp-chatbot-notification-close">X</span> </div>
358 + <?php
359 + if (get_option('wp_chatbot_custom_agent_path') != "" && get_option('wp_chatbot_agent_image') == "custom-agent.png") {
360 + $wp_chatbot_custom_icon_path = get_option('wp_chatbot_custom_agent_path');
361 + } else if (get_option('wp_chatbot_custom_agent_path') != "" && get_option('wp_chatbot_agent_image') != "custom-agent.png") {
362 + $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_agent_image');
363 + } else {
364 + $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . 'custom-agent.png';
365 + }
366 + ?>
367 + <div class="wp-chatbot-notification-agent-profile">
368 + <div class="wp-chatbot-notification-widget-avatar"><img
369 + src="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>" alt=""></div>
370 + <div class="wp-chatbot-notification-welcome"><?php echo wp_kses_post(wpb_randmom_message_handle(maybe_unserialize(get_option('qlcd_wp_chatbot_welcome')))) . ' <strong>' . esc_html(get_option('qlcd_wp_chatbot_host')) . '</strong>'; ?></div>
371 + </div>
372 + <div class="wp-chatbot-notification-message"><?php echo wp_kses_post(wpb_randmom_message_handle(maybe_unserialize(get_option('qlcd_wp_chatbot_notifications')))); ?></div>
373 + </div>
374 + <!--wp-chatbot-board-container-->
375 + <div id="wp-chatbot-ball" class="">
376 + <div class="wp-chatbot-ball">
377 + <div class="wp-chatbot-ball-animator wp-chatbot-ball-animation-switch"></div>
378 + <?php
379 + if (get_option('wp_chatbot_custom_icon_path') != "" && get_option('wp_chatbot_icon') == "custom.png") {
380 + $wp_chatbot_custom_icon_path = get_option('wp_chatbot_custom_icon_path');
381 + } else if (get_option('wp_chatbot_custom_icon_path') != "" && get_option('wp_chatbot_icon') != "custom.png") {
382 + $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_icon');
383 + } else {
384 + $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . 'custom.png';
385 + }
386 + ?>
387 + <img src="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>"
388 + alt="wpChatIcon"> <!--<span class="wp-chatbot-ball-cart-items"><?php echo esc_html( $cart_items_number ); ?></span>--> </div>
389 + </div>
390 + <!-- wp-chatbot-board-container-->
391 + <?php endif; ?>
392 + <!--container-->
393 + <!--wp-chatbot-ball-wrapper-->
394 + </div>
395 +<?php } ?>
396 +<?php
397 +//Create shortcode for wpwBot for pages.
398 +add_shortcode('wpbot-page', 'wp_chatbot_page_short_code');
399 +function wp_chatbot_page_short_code(){
400 + ob_start();
401 + wp_chatbot_page_dom();
402 + $content = ob_get_clean();
403 + return $content;
404 +}
405 +function wp_chatbot_page_dom(){ ?>
406 + <style>
407 + <?php
408 + if(get_option('wp_chatbot_custom_css')!=""){
409 + //Sanitization to be checked
410 + // phpcs:ignore
411 + echo sanitize_text_field(get_option('wp_chatbot_custom_css'));
412 + } ?>
413 + </style>
414 + <?php
415 + //Get wpcommerce cart
416 +
417 + $qcld_wb_chatbot_theme = get_option('qcld_wb_chatbot_theme');
418 + $wp_chatbot_enable_rtl = "";
419 + if (get_option('enable_wp_chatbot_rtl') == 1) {
420 + $wp_chatbot_enable_rtl .= "wp-chatbot-rtl";
421 + }
422 + if (file_exists(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/shortcode.php')) {
423 + require_once(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/shortcode.php');
424 + } else {
425 + echo "<h2>" . esc_html__('No WPBot ShortCode Theme Found!', 'wpchatbot') . "</h2>";
426 + }
427 +}
428 +//shortcode for wpWBot mobile app
429 +add_shortcode('wpwbot_app', 'wp_chatbot_mobile_app_short_code');
430 +function wp_chatbot_mobile_app_short_code(){ ?>
431 + <style>
432 + <?php
433 + if(get_option('wp_chatbot_custom_css')!=""){
434 + //Sanitization to be checked
435 + // phpcs:ignore
436 + echo sanitize_text_field(get_option('wp_chatbot_custom_css'));
437 + }
438 + ?>
439 + </style>
440 + <?php if (get_option('qcld_wb_chatbot_change_bg') == 1) {
441 + if (get_option('qcld_wb_chatbot_board_bg_path') != "") {
442 + $qcld_wb_chatbot_board_bg_path = get_option('qcld_wb_chatbot_board_bg_path');
443 + } else {
444 + $qcld_wb_chatbot_board_bg_path = QCLD_wpCHATBOT_IMG_URL . 'background/background.png';
445 + }
446 + ?>
447 + <style>
448 + .wp-chatbot-container {
449 + background: url(<?php echo esc_url($qcld_wb_chatbot_board_bg_path) ;?>) no-repeat top right !important;
450 + }
451 + </style>
452 +<?php }
453 + $wp_chatbot_enable_rtl = "";
454 + if (get_option('enable_wp_chatbot_rtl') == '1') {
455 + $wp_chatbot_enable_rtl .= "wp-chatbot-rtl";
456 + }
457 + ?>
458 + <div id="wp-chatbot-chat-app-shortcode-container" class="<?php echo esc_attr($wp_chatbot_enable_rtl); ?>">
459 + <?php
460 + // keep traking app template.
461 + $template_app = 'yes';
462 + //Get wpcommerce cart
463 +
464 + //Handling shortcode enqeue and remove features part.
465 + define('wpCOMMERCE', true);
466 + wp_enqueue_script('jquery');
467 +
468 +
469 + wp_enqueue_script('wc-address-i18n');
470 + wp_enqueue_script('wc-country-select');
471 +
472 +
473 + // add the action
474 + if (isset($_GET['from']) && $_GET['from'] == 'app') {
475 + if (!isset($_COOKIE['from_app'])) {
476 + setcookie('from_app', 'yes', time() + 3600);
477 + }
478 + }
479 + $qcld_wb_chatbot_theme = get_option('qcld_wb_chatbot_theme');
480 + if (file_exists(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/template.php')) {
481 + require_once(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/template.php');
482 + } else {
483 + echo "<h2>" . esc_html__('No WPBot Theme Found!', 'wpchatbot') . "</h2>";
484 + }
485 + ?>
486 + </div>
487 + <?php
488 +}
464 489
465 490 /**
466 491 * wpwBot Search keyword product
467 492 */
@@ -467,16 +492,9 @@
467 492 */
468 493 add_action('wp_ajax_qcld_wb_chatbot_keyword', 'qcld_wb_chatbot_keyword');
469 494 add_action('wp_ajax_nopriv_qcld_wb_chatbot_keyword', 'qcld_wb_chatbot_keyword');
470 495 function qcld_wb_chatbot_keyword(){
471 - // Verify nonce for security
472 - $nonce = isset($_POST['security']) ? sanitize_text_field(wp_unslash($_POST['security'])) : (isset($_POST['nonce']) ? sanitize_text_field(wp_unslash($_POST['nonce'])) : '');
473 - if ( ! wp_verify_nonce( $nonce, 'wp_chatbot' ) && ! wp_verify_nonce( $nonce, 'qcsecretbotnonceval123qc' ) ) {
474 - wp_send_json_error( array( 'status' => 'fail', 'message' => 'Security check failed.' ) );
475 - wp_die();
476 - }
477 -
478 - $keyword = sanitize_text_field(wp_unslash($_POST['keyword']));
496 + $keyword = sanitize_text_field($_POST['keyword']);
479 497 $product_per_page = get_option('qlcd_wp_chatbot_ppp') != '' ? get_option('qlcd_wp_chatbot_ppp') : 10;
480 498 if (get_option('qlcd_wp_chatbot_search_option') == 'standard') {
481 499 $product_orderby = sanitize_text_field(get_option('qlcd_wp_chatbot_product_orderby') != '' ? get_option('qlcd_wp_chatbot_product_orderby') : 'title');
482 500 $product_order = sanitize_text_field(get_option('qlcd_wp_chatbot_product_order') != '' ? get_option('qlcd_wp_chatbot_product_order') : 'ASC');
@@ -522,9 +540,9 @@
522 540 endwhile;
523 541 wp_reset_postdata();
524 542 $html .= '</ul>';
525 543 if ($total_product_num > $product_per_page && $product_per_page > 0 ) {
526 - $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . esc_attr($keyword) . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
544 + $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . $keyword . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
527 545 }
528 546 }
529 547 $html .= '</div>';
530 548 } else if (get_option('qlcd_wp_chatbot_search_option') == 'advanced') {
@@ -552,9 +570,9 @@
552 570 }
553 571 }
554 572 $html .= '</ul>';
555 573 if ($total_product_num > $product_per_page && $product_per_page > 0) {
556 - $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . esc_attr($more_product_ids) . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
574 + $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . $more_product_ids . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
557 575 }
558 576 }
559 577 $html .= '</div>';
560 578 }
@@ -569,15 +587,16 @@
569 587 add_action('wp_ajax_nopriv_qcld_wb_chatbot_category', 'qcld_wb_chatbot_category');
570 588 function qcld_wb_chatbot_category(){
571 589 $category_type="common";
572 590 if (get_option('wp_chatbot_show_parent_category') != "") {
573 - $terms = get_terms( array( 'taxonomy' => 'product_cat', 'parent' => 0, 'hide_empty' => true, 'fields' => 'all' ) );
591 + $terms = get_terms('product_cat', array('parent' => 0, 'hide_empty' => true, 'fields' => 'all'));
592 +
574 593 } else {
575 - $terms = get_terms( array( 'taxonomy' => 'product_cat', 'hide_empty' => true, 'fields' => 'all' ) );
594 + $terms = get_terms('product_cat', array('hide_empty' => true, 'fields' => 'all'));
576 595 }
577 596 $html = "";
578 597 foreach ($terms as $term) {
579 - $child_terms=get_terms( array( 'taxonomy' => 'product_cat', 'parent' => $term->term_id, 'hide_empty' => true, 'fields' => 'all' ) );
598 + $child_terms=get_terms('product_cat', array('parent' => $term->term_id, 'hide_empty' => true, 'fields' => 'all'));
580 599 if(get_option('wp_chatbot_show_sub_category')==1 && count($child_terms) >0){
581 600 $category_type="hasChilds";
582 601 }
583 602 $html .= '<span class="qcld-chatbot-product-category" data-category-type="' . $category_type . '" data-category-slug="' . $term->slug . '" data-category-id="' . $term->term_id . '">' . $term->name . '</span>';
@@ -590,10 +609,10 @@
590 609 */
591 610 add_action('wp_ajax_qcld_wb_chatbot_sub_category', 'qcld_wb_chatbot_sub_category');
592 611 add_action('wp_ajax_nopriv_qcld_wb_chatbot_sub_category', 'qcld_wb_chatbot_sub_category');
593 612 function qcld_wb_chatbot_sub_category(){
594 - $parent_id = intval( wp_unslash( $_POST['parent_id'] ) );
595 - $terms = get_terms( array( 'taxonomy' => 'product_cat', 'parent' => $parent_id, 'hide_empty' => true, 'fields' => 'all' ) );
613 + $parent_id = stripslashes($_POST['parent_id']);
614 + $terms = get_terms('product_cat', array('parent' => $parent_id, 'hide_empty' => true, 'fields' => 'all'));
596 615 $html = "";
597 616 foreach ($terms as $term) {
598 617 $html .= '<span class="qcld-chatbot-product-category" data-category-type="common" data-category-slug="' . $term->slug . '" data-category-id="' . $term->term_id . '">' . $term->name . '</span>';
599 618 }
@@ -605,9 +624,9 @@
605 624 */
606 625 add_action('wp_ajax_qcld_wb_chatbot_category_products', 'qcld_wb_chatbot_category_products');
607 626 add_action('wp_ajax_nopriv_qcld_wb_chatbot_category_products', 'qcld_wb_chatbot_category_products');
608 627 function qcld_wb_chatbot_category_products(){
609 - $category_id = intval( wp_unslash( $_POST['category'] ) );
628 + $category_id = stripslashes($_POST['category']);
610 629 $product_per_page = sanitize_text_field(get_option('qlcd_wp_chatbot_ppp') != '' ? get_option('qlcd_wp_chatbot_ppp') : 10);
611 630 $product_orderby = sanitize_text_field(get_option('qlcd_wp_chatbot_product_orderby') != '' ? get_option('qlcd_wp_chatbot_product_orderby') : 'title');
612 631 $product_order = sanitize_text_field(get_option('qlcd_wp_chatbot_product_order') != '' ? get_option('qlcd_wp_chatbot_product_order') : 'ASC');
613 632 //Merging all query together.
@@ -844,11 +863,11 @@
844 863 //load more
845 864 add_action('wp_ajax_qcld_wb_chatbot_load_more', 'qcld_wb_chatbot_load_more');
846 865 add_action('wp_ajax_nopriv_qcld_wb_chatbot_load_more', 'qcld_wb_chatbot_load_more');
847 866 function qcld_wb_chatbot_load_more(){
848 - $offset = intval( wp_unslash( $_POST['offset'] ) );
849 - $search_type = sanitize_text_field( wp_unslash( $_POST['search_type'] ) );
850 - $search_term = sanitize_text_field( wp_unslash( $_POST['search_term'] ) );
867 + $offset = stripslashes($_POST['offset']);
868 + $search_type = stripslashes($_POST['search_type']);
869 + $search_term = stripslashes($_POST['search_term']);
851 870 $product_per_page = sanitize_text_field(get_option('qlcd_wp_chatbot_ppp') != '' ? get_option('qlcd_wp_chatbot_ppp') : 10);
852 871 $product_orderby = sanitize_text_field(get_option('qlcd_wp_chatbot_product_orderby') != '' ? get_option('qlcd_wp_chatbot_product_orderby') : 'title');
853 872 $product_order = sanitize_text_field(get_option('qlcd_wp_chatbot_product_order') != '' ? get_option('qlcd_wp_chatbot_product_order') : 'ASC');
854 873 $next_offset = intval($product_per_page + $offset);
@@ -979,9 +998,9 @@
979 998 //product details
980 999 add_action('wp_ajax_qcld_wb_chatbot_product_details', 'qcld_wb_chatbot_product_details');
981 1000 add_action('wp_ajax_nopriv_qcld_wb_chatbot_product_details', 'qcld_wb_chatbot_product_details');
982 1001 function qcld_wb_chatbot_product_details(){
983 - $product_id = intval( wp_unslash( $_POST['wp_chatbot_pid'] ) );
1002 + $product_id = stripslashes($_POST['wp_chatbot_pid']);
984 1003 //Tracking product view from chat board
985 1004 wp_chatbot_view_track_product_by_id($product_id);
986 1005 //wpcommerce product factory
987 1006 $wc_pf = new WC_Product_Factory();
@@ -1009,9 +1028,9 @@
1009 1028 }
1010 1029 }
1011 1030 $product_image .= '</ul></div>';
1012 1031 $product_price = '<p class="wp-chatbot-product-price" id="wp-chatbot-product-price">' . $product->get_price_html() . '</p>';
1013 - $product_sku = '<p class="wp-chatbot-product-sku"> ' . __('SKU', 'chatbot') . ' : ' . $product->get_sku() . '</p>';
1032 + $product_sku = '<p class="wp-chatbot-product-sku"> ' . __('SKU', 'wpchatbot') . ' : ' . $product->get_sku() . '</p>';
1014 1033 //if ( $product->is_in_stock() || $product->is_purchasable() )
1015 1034 //Handle variable product start
1016 1035 $variations = "";
1017 1036 $add_cart_button = "";
@@ -1054,11 +1073,10 @@
1054 1073 $variations .= '<label for="' . sanitize_title($name) . '">' . $title . '</label>';
1055 1074 $variations .= '<select id="' . esc_attr(sanitize_title($name)) . '" name="attribute_' . sanitize_title($name) . '" data-attribute_name="attribute_' . sanitize_title($name) . '" class="each_attribute">';
1056 1075 $variations .= '<option value="">' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_choose_option')))) . '</option>';
1057 1076 foreach ($values as $value) {
1058 - $attr_key = 'attribute_' . sanitize_title( $name );
1059 - if ( isset( $_REQUEST[ $attr_key ] ) ) { // phpcs:ignore WordPress.Security.NonceVerification
1060 - $selected_value = sanitize_text_field( wp_unslash( $_REQUEST[ $attr_key ] ) );
1077 + if (isset($_REQUEST['attribute_' . sanitize_title($name)])) {
1078 + $selected_value = $_REQUEST['attribute_' . sanitize_title($name)];
1061 1079 } else {
1062 1080 $selected_value = '';
1063 1081 }
1064 1082 $variations .= '<option value="' . esc_attr(strtolower($value)) . '"' . selected($selected_value, $value, false) . '>' . apply_filters('wpcommerce_variation_option_name', $value) . '</option>';
@@ -1079,15 +1097,15 @@
1079 1097 $response = array('title' => $product_title, 'description' => $product_desc, 'image' => $product_image, 'price' => $product_price, 'sku' => $product_sku, 'quantity' => $product_quantity, 'buttton' => $add_cart_button, 'variation' => $variations, 'type' => $product_type, 'debug' => $debug);
1080 1098 wp_send_json($response);
1081 1099 }
1082 1100 //Add to cart for variable product.
1083 -add_action('wp_ajax_qcld_variable_add_to_cart', 'qcld_variable_add_to_cart');
1084 -add_action('wp_ajax_nopriv_qcld_variable_add_to_cart', 'qcld_variable_add_to_cart');
1085 -function qcld_variable_add_to_cart(){
1086 - $product_id = intval( wp_unslash( $_POST['p_id'] ) );
1087 - $quantity = intval( wp_unslash( $_POST['quantity'] ) );
1088 - $variations_id = intval( wp_unslash( $_POST['variations_id'] ) );
1089 - $attrs = isset( $_POST['attributes'] ) ? array_map( 'sanitize_text_field', wp_unslash( (array) $_POST['attributes'] ) ) : array();
1101 +add_action('wp_ajax_variable_add_to_cart', 'qcld_wb_chatbot_variable_add_to_cart');
1102 +add_action('wp_ajax_nopriv_variable_add_to_cart', 'qcld_wb_chatbot_variable_add_to_cart');
1103 +function qcld_wb_chatbot_variable_add_to_cart(){
1104 + $product_id = stripslashes($_POST['p_id']);
1105 + $quantity = stripslashes($_POST['quantity']);
1106 + $variations_id = stripslashes($_POST['variations_id']);
1107 + $attrs = stripslashes($_POST['attributes']);
1090 1108 //echo wp_send_json(array('p_id'=>$product_id,'qnty'=>$quantity,'id'=>$variations_id,'att'=>$attrs));
1091 1109 $attributes = array();
1092 1110 foreach ($attrs as $attr) {
1093 1111 $single = explode("#", $attr);
@@ -1107,10 +1125,10 @@
1107 1125 //Add to cart for simple product.
1108 1126 add_action('wp_ajax_qcld_wb_chatbot_add_to_cart', 'qcld_wb_chatbot_add_to_cart');
1109 1127 add_action('wp_ajax_nopriv_qcld_wb_chatbot_add_to_cart', 'qcld_wb_chatbot_add_to_cart');
1110 1128 function qcld_wb_chatbot_add_to_cart(){
1111 - $product_id = intval( wp_unslash( $_POST['product_id'] ) );
1112 - $product_quantity = intval( wp_unslash( $_POST['quantity'] ) );
1129 + $product_id = stripslashes($_POST['product_id']);
1130 + $product_quantity = stripslashes($_POST['quantity']);
1113 1131 global $wpcommerce;
1114 1132 $result = $wpcommerce->cart->add_to_cart($product_id, $product_quantity);
1115 1133 if ($result != false) {
1116 1134 wp_send_json('simple');
@@ -1121,19 +1139,15 @@
1121 1139 //Support part
1122 1140 add_action('wp_ajax_qcld_wb_chatbot_support_email', 'qcld_wb_chatbot_support_email');
1123 1141 add_action('wp_ajax_nopriv_qcld_wb_chatbot_support_email', 'qcld_wb_chatbot_support_email');
1124 1142 function qcld_wb_chatbot_support_email(){
1125 - $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( wp_unslash( $_POST['nonce'] ) ) : '';
1126 - if ( ! wp_verify_nonce( $nonce, 'qcsecretbotnonceval123qc' ) ) {
1127 - wp_send_json_error( array( 'error' => esc_html__( 'Error: Invalid nonce verification.', 'chatbot' ) ) );
1128 - }
1129 - $name = trim(sanitize_text_field(wp_unslash($_POST['name'])));
1130 - $email = sanitize_email(wp_unslash($_POST['email']));
1131 - $message = sanitize_text_field(wp_unslash($_POST['message']));
1143 + $name = trim(sanitize_text_field($_POST['name']));
1144 + $email = sanitize_email($_POST['email']);
1145 + $message = sanitize_text_field($_POST['message']);
1132 1146 $subject = sanitize_text_field(get_option('qlcd_wp_chatbot_email_sub') != '' ? get_option('qlcd_wp_chatbot_email_sub') : 'Support Email from wpWBot by Client');
1133 1147 //Extract Domain
1134 1148 $url = get_site_url();
1135 - $url = wp_parse_url($url);
1149 + $url = parse_url($url);
1136 1150 $domain = $url['host'];
1137 1151 //$admin_email = "admin@" . $domain;
1138 1152 $admin_email = sanitize_email(get_option('admin_email'));
1139 1153 $toEmail = sanitize_email(get_option('qlcd_wp_chatbot_admin_email') != '' ? get_option('qlcd_wp_chatbot_admin_email') : $admin_email);
@@ -1143,8 +1157,9 @@
1143 1157 $fromEmail = get_option('qlcd_wp_chatbot_from_email');
1144 1158 }else{
1145 1159 $fromEmail = "wordpress@" . $domain;
1146 1160 }
1161 +
1147 1162 //Starting messaging and status.
1148 1163 $response['status'] = 'fail';
1149 1164 $response['message'] = str_replace('\\', '',wp_kses_post(get_option('qlcd_wp_chatbot_email_fail')));
1150 1165 if (filter_var($email, FILTER_VALIDATE_EMAIL) === false) {
@@ -1152,14 +1167,14 @@
1152 1167 $response['status'] = 'fail';
1153 1168 } else {
1154 1169 //build email body
1155 1170 $bodyContent = "";
1156 - $bodyContent .= '<p><strong>' . __('Support Request Details', 'chatbot') . ':</strong></p><hr>';
1157 - $bodyContent .= '<p>' . __('Name', 'chatbot') . ' : ' . $name . '</p>';
1158 - $bodyContent .= '<p>' . __('Email', 'chatbot') . ' : ' . $email . '</p>';
1159 - $bodyContent .= '<p>' . __('Subject', 'chatbot') . ' : ' . $subject . '</p>';
1160 - $bodyContent .= '<p>' . __('Message', 'chatbot') . ' : ' . $message . '</p>';
1161 - $bodyContent .= '<p>' . __('Mail Generated on', 'chatbot') . ': ' . current_time('F j, Y, g:i a') . '</p>';
1171 + $bodyContent .= '<p><strong>' . __('Support Request Details', 'wpchatbot') . ':</strong></p><hr>';
1172 + $bodyContent .= '<p>' . __('Name', 'wpchatbot') . ' : ' . $name . '</p>';
1173 + $bodyContent .= '<p>' . __('Email', 'wpchatbot') . ' : ' . $email . '</p>';
1174 + $bodyContent .= '<p>' . __('Subject', 'wpchatbot') . ' : ' . $subject . '</p>';
1175 + $bodyContent .= '<p>' . __('Message', 'wpchatbot') . ' : ' . $message . '</p>';
1176 + $bodyContent .= '<p>' . __('Mail Generated on', 'wpchatbot') . ': ' . current_time('F j, Y, g:i a') . '</p>';
1162 1177 $to = $toEmail;
1163 1178 $body = $bodyContent;
1164 1179 $headers = array();
1165 1180 $headers[] = 'Content-Type: text/html; charset=UTF-8';
@@ -1171,9 +1186,9 @@
1171 1186 $response['message'] = str_replace('\\', '',wp_kses_post(get_option('qlcd_wp_chatbot_email_sent')));
1172 1187 }
1173 1188
1174 1189 }
1175 - echo wp_json_encode($response);
1190 + echo json_encode($response);
1176 1191 die();
1177 1192 }
1178 1193 //Support Phone
1179 1194 add_action('wp_ajax_qcld_wb_chatbot_support_phone', 'qcld_wb_chatbot_support_phone');
@@ -1178,15 +1193,14 @@
1178 1193 //Support Phone
1179 1194 add_action('wp_ajax_qcld_wb_chatbot_support_phone', 'qcld_wb_chatbot_support_phone');
1180 1195 add_action('wp_ajax_nopriv_qcld_wb_chatbot_support_phone', 'qcld_wb_chatbot_support_phone');
1181 1196 function qcld_wb_chatbot_support_phone(){
1182 - check_ajax_referer('qcsecretbotnonceval123qc', 'nonce');
1183 - $name = trim(sanitize_text_field(wp_unslash($_POST['name'])));
1184 - $phone =sanitize_text_field(wp_unslash($_POST['phone']));
1197 + $name = trim(sanitize_text_field($_POST['name']));
1198 + $phone =sanitize_text_field($_POST['phone']);
1185 1199 $subject = 'WPBot Support Mail Request for Call Back';
1186 1200 //Extract Domain
1187 1201 $url = get_site_url();
1188 - $url = wp_parse_url($url);
1202 + $url = parse_url($url);
1189 1203 $domain = $url['host'];
1190 1204 //$admin_email = "admin@" . $domain;
1191 1205 $admin_email = get_option('admin_email');
1192 1206 $toEmail = sanitize_email(get_option('qlcd_wp_chatbot_admin_email') != '' ? get_option('qlcd_wp_chatbot_admin_email') : $admin_email);
@@ -1201,14 +1215,14 @@
1201 1215 $response['status'] = 'fail';
1202 1216 $response['message'] = str_replace('\\', '',wp_kses_post(get_option('qlcd_wp_chatbot_phone_fail')));
1203 1217 //build email body
1204 1218 $bodyContent = "";
1205 - $bodyContent .= '<p><strong>' . __('Support Request Details', 'chatbot') . ':</strong></p><hr>';
1206 - $bodyContent .= '<p>' . __('Name', 'chatbot') . ' : ' . $name . '</p>';
1207 - $bodyContent .= '<p>' . __('Phone', 'chatbot') . ' : ' . $phone . '</p>';
1208 - $bodyContent .= '<p>' . __('Subject', 'chatbot') . ' : ' . $subject . '</p>';
1209 - $bodyContent .= '<p>' . __('Message', 'chatbot') . ' : ' . __(' Call me at ', 'chatbot'). $phone . '</p>';
1210 - $bodyContent .= '<p>' . __('Mail Generated on', 'chatbot') . ': ' . current_time('F j, Y, g:i a') . '</p>';
1219 + $bodyContent .= '<p><strong>' . __('Support Request Details', 'wpchatbot') . ':</strong></p><hr>';
1220 + $bodyContent .= '<p>' . __('Name', 'wpchatbot') . ' : ' . $name . '</p>';
1221 + $bodyContent .= '<p>' . __('Phone', 'wpchatbot') . ' : ' . $phone . '</p>';
1222 + $bodyContent .= '<p>' . __('Subject', 'wpchatbot') . ' : ' . $subject . '</p>';
1223 + $bodyContent .= '<p>' . __('Message', 'wpchatbot') . ' : ' . __(' Call me at ', 'wpchatbot'). $phone . '</p>';
1224 + $bodyContent .= '<p>' . __('Mail Generated on', 'wpchatbot') . ': ' . current_time('F j, Y, g:i a') . '</p>';
1211 1225 $to = $toEmail;
1212 1226 $body = $bodyContent;
1213 1227 $headers = array();
1214 1228 $headers[] = 'Content-Type: text/html; charset=UTF-8';
@@ -1218,15 +1232,15 @@
1218 1232 if ($result) {
1219 1233 $response['status'] = 'success';
1220 1234 $response['message'] = str_replace('\\', '',wp_kses_post(get_option('qlcd_wp_chatbot_phone_sent')));
1221 1235 }
1222 - echo wp_json_encode($response);
1236 + echo json_encode($response);
1223 1237 die();
1224 1238 }
1225 1239 // Order Status part. removed
1226 1240
1227 1241 function wpb_randmom_message_handle($items){
1228 - return $items[wp_rand(0, count($items) - 1)];
1242 + return $items[rand(0, count($items) - 1)];
1229 1243 }
1230 1244 function qcld_wb_chatbot_func_str_replace($messages = array()){
1231 1245 $refined_mesgses = array();
1232 1246 foreach ($messages as $message) {
@@ -1241,10 +1255,10 @@
1241 1255 // First check the nonce, if it fails the function will break
1242 1256 check_ajax_referer('wpwbot-order-nonce', 'security');
1243 1257 // Nonce is checked, get the POST data and sign user on
1244 1258 $info = array();
1245 - $info['user_login'] = trim(sanitize_text_field(wp_unslash($_POST['user_name'])));
1246 - $info['user_password'] = trim(sanitize_text_field(wp_unslash($_POST['user_pass'])));
1259 + $info['user_login'] = trim(sanitize_text_field($_POST['user_name']));
1260 + $info['user_password'] = trim(sanitize_text_field($_POST['user_pass']));
1247 1261 $info['remember'] = true;
1248 1262 $user_signon = wp_signon($info, false);
1249 1263 $response = array();
1250 1264 if (is_wp_error($user_signon)) {
@@ -1284,12 +1298,12 @@
1284 1298 if ($response['order_num'] > 0) {
1285 1299 $response['message'] .= wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_order_found'))));
1286 1300 $order_html .= '<div class="wp-chatbot-orders-container">
1287 1301 <div class="wp-chatbot-orders-header">
1288 - <div class="order-id">' . __('ID', 'chatbot') . '</div>
1289 - <div class="order-date">' . __('Date', 'chatbot') . ' </div>
1290 - <div class="order-items">' . __('Items', 'chatbot') . '</div>
1291 - <div class="order-status">' . __('Status', 'chatbot') . '</div>
1302 + <div class="order-id">' . __('ID', 'wpchatbot') . '</div>
1303 + <div class="order-date">' . __('Date', 'wpchatbot') . ' </div>
1304 + <div class="order-items">' . __('Items', 'wpchatbot') . '</div>
1305 + <div class="order-status">' . __('Status', 'wpchatbot') . '</div>
1292 1306 </div>';
1293 1307 foreach ($customer_orders as $order) {
1294 1308 //Formatting order summery
1295 1309 if (isset($_COOKIE['from_app']) && $_COOKIE['from_app'] == 'yes') {
@@ -1300,9 +1314,9 @@
1300 1314 $order_url = '<a href="' . get_url(get_permalink(get_option('wpcommerce_myaccount_page_id')) . '/view-order/' . $order->ID) . '" target="_blank" >' . $order->ID . '</a>';
1301 1315 }
1302 1316 $order_html .= '<div class="wp-chatbot-orders-single">
1303 1317 <div class="order-id"> ' . $order_url . '</div>
1304 - <div class="order-date"> <p>' . gmdate("m/d/Y", strtotime($order->post_date)) . '</p> </div>
1318 + <div class="order-date"> <p>' . date("m/d/Y", strtotime($order->post_date)) . '</p> </div>
1305 1319 <div class="order-items">';
1306 1320 $singleOrder = new WC_Order($order->ID);
1307 1321 $items = $singleOrder->get_items();
1308 1322 foreach ($items as $item) {
@@ -1402,9 +1416,9 @@
1402 1416 $html .= get_the_post_thumbnail(get_the_ID(), 'shop_catalog') . '
1403 1417 <div class="wp-chatbot-product-summary">
1404 1418 <div class="wp-chatbot-product-table">
1405 1419 <div class="wp-chatbot-product-table-cell">
1406 - <h3 class="wp-chatbot-product-title">' . esc_html($product->post->post_title) . '</h3>
1420 + <h3 class="wp-chatbot-product-title">' . $product->post->post_title . '</h3>
1407 1421 <div class="price">' . $product->get_price_html() . '</div>';
1408 1422 $html .= ' </div>
1409 1423 </div>
1410 1424 </div></a>
@@ -1473,9 +1487,9 @@
1473 1487 $html .= get_the_post_thumbnail(get_the_ID(), 'shop_catalog') . '
1474 1488 <div class="wp-chatbot-product-summary">
1475 1489 <div class="wp-chatbot-product-table">
1476 1490 <div class="wp-chatbot-product-table-cell">
1477 - <h3 class="wp-chatbot-product-title">' . esc_html($product->post->post_title) . '</h3>
1491 + <h3 class="wp-chatbot-product-title">' . $product->post->post_title . '</h3>
1478 1492 <div class="price">' . $product->get_price_html() . '</div>';
1479 1493 $html .= ' </div>
1480 1494 </div>
1481 1495 </div></a>
@@ -1485,9 +1499,9 @@
1485 1499 wp_reset_postdata();
1486 1500 $html .= '</ul></div>';
1487 1501 } else {
1488 1502 $html .= '<div class="wp-chatbot-products-area">';
1489 - $html .= '<p style="text-align: center">' . __('You have no products', 'chatbot') . ' !';
1503 + $html .= '<p style="text-align: center">' . __('You have no products', 'wpchatbot') . ' !';
1490 1504 $html .= '</div>';
1491 1505 }
1492 1506 return $html;
1493 1507 }
@@ -1649,12 +1663,11 @@
1649 1663 //Updating the cart items.
1650 1664 add_action('wp_ajax_qcld_wb_chatbot_update_cart_item_number', 'qcld_wb_chatbot_update_cart_item_number');
1651 1665 add_action('wp_ajax_nopriv_qcld_wb_chatbot_update_cart_item_number', 'qcld_wb_chatbot_update_cart_item_number');
1652 1666 function qcld_wb_chatbot_update_cart_item_number(){
1653 - check_ajax_referer( 'wp_chatbot', 'nonce' );
1654 1667 //getting cart items n
1655 - $cart_item_key = sanitize_text_field(wp_unslash($_POST['cart_item_key']));
1656 - $qnty = sanitize_text_field(wp_unslash($_POST['qnty']));
1668 + $cart_item_key = sanitize_text_field($_POST['cart_item_key']);
1669 + $qnty = sanitize_text_field($_POST['qnty']);
1657 1670 global $wpcommerce;
1658 1671 $result = $wpcommerce->cart->set_quantity($cart_item_key, $qnty);
1659 1672 wp_send_json($result);
1660 1673 }
@@ -1661,11 +1674,10 @@
1661 1674 //Show item after removing from cart page.
1662 1675 add_action('wp_ajax_qcld_wb_chatbot_cart_item_remove', 'qcld_wb_chatbot_cart_item_remove');
1663 1676 add_action('wp_ajax_nopriv_qcld_wb_chatbot_cart_item_remove', 'qcld_wb_chatbot_cart_item_remove');
1664 1677 function qcld_wb_chatbot_cart_item_remove(){
1665 - check_ajax_referer( 'wp_chatbot', 'nonce' );
1666 1678 //getting cart items n
1667 - $cart_item_key = sanitize_text_field(wp_unslash($_POST['cart_item']));
1679 + $cart_item_key = sanitize_text_field($_POST['cart_item']);
1668 1680 global $wpcommerce;
1669 1681 $result = $wpcommerce->cart->remove_cart_item($cart_item_key);
1670 1682 wp_send_json($result);
1671 1683 }
@@ -1702,9 +1714,9 @@
1702 1714 $response = array('status' => $status, 'html' => $html);
1703 1715 wp_send_json($response);
1704 1716 }
1705 1717 //_dynamic_intent
1706 -function qcld_dynamic_intent(){
1718 +function qc_dynamic_intent(){
1707 1719 global $wpdb;
1708 1720 $intents = array();
1709 1721
1710 1722 $ai_df = get_option('enable_wp_chatbot_dailogflow');
@@ -1721,9 +1733,9 @@
1721 1733
1722 1734 if(class_exists('Qcformbuilder_Forms_Admin')){
1723 1735
1724 1736
1725 - $results = $wpdb->get_results($wpdb->prepare("SELECT * FROM ". $wpdb->prefix."wfb_forms WHERE type= %s",'primary')); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1737 + $results = $wpdb->get_results($wpdb->prepare("SELECT * FROM ". $wpdb->prefix."wfb_forms WHERE type= %s",'primary')); //DB Call OK, No Caching OK
1726 1738
1727 1739 if(!empty($results)){
1728 1740
1729 1741 foreach($results as $result){
@@ -1748,10 +1760,10 @@
1748 1760 // function qcld_wb_chatbot_checkout_user_login(){
1749 1761 // // Nonce is checked, get the POST data and sign user on
1750 1762 // $info = array();
1751 1763 // //$info['nonce'] = $_POST['nonce_val'];
1752 -// $info['user_login'] = trim(sanitize_text_field(wp_unslash($_POST['user_name'])));
1753 -// $info['user_password'] = trim(sanitize_text_field(wp_unslash($_POST['user_pass'])));
1764 +// $info['user_login'] = trim(sanitize_text_field($_POST['user_name']));
1765 +// $info['user_password'] = trim(sanitize_text_field($_POST['user_pass']));
1754 1766 // $info['remember'] = true;
1755 1767 // $user_signon = wp_signon($info, false);
1756 1768 // // $response=$info;
1757 1769 // $response = array();
@@ -1792,16 +1804,15 @@
1792 1804 add_action('init', 'wp_chatbot_create_app_checkout_thankyou_page');
1793 1805 function wp_chatbot_create_app_checkout_thankyou_page(){
1794 1806 if (get_option('wp_chatbot_app_pages') == 1) {
1795 1807 //Mobile App page create
1796 - $existing_app = new WP_Query( array( 'post_type' => 'page', 'name' => 'wpwbot-mobile-app', 'post_status' => 'publish', 'posts_per_page' => 1 ) );
1797 - if ( ! $existing_app->have_posts() ) {
1808 + if (get_page_by_title('wpwBot Mobile App') == NULL) {
1798 1809 //post status and options
1799 1810 $app_page = array(
1800 1811 'comment_status' => 'closed',
1801 1812 'ping_status' => 'closed',
1802 1813 'post_author' => get_current_user_id(),
1803 - 'post_date' => gmdate('Y-m-d H:i:s'),
1814 + 'post_date' => date('Y-m-d H:i:s'),
1804 1815 'post_status' => 'publish',
1805 1816 'post_title' => 'wpwBot Mobile App',
1806 1817 'post_name' => 'wpwbot-mobile-app',
1807 1818 'post_type' => 'page',
@@ -1811,16 +1822,15 @@
1811 1822 //save the id in the database
1812 1823 update_option('wp_chatbot_app_checkout', $wpwbot_app);
1813 1824 }
1814 1825 //App checkout page create
1815 - $existing_checkout = new WP_Query( array( 'post_type' => 'page', 'name' => 'wpwbot-app-checkout', 'post_status' => 'publish', 'posts_per_page' => 1 ) );
1816 - if ( ! $existing_checkout->have_posts() ) {
1826 + if (get_page_by_title('wpwBot App Checkout') == NULL) {
1817 1827 //post status and options
1818 1828 $checkout_page = array(
1819 1829 'comment_status' => 'closed',
1820 1830 'ping_status' => 'closed',
1821 1831 'post_author' => get_current_user_id(),
1822 - 'post_date' => gmdate('Y-m-d H:i:s'),
1832 + 'post_date' => date('Y-m-d H:i:s'),
1823 1833 'post_status' => 'publish',
1824 1834 'post_title' => 'wpwBot App Checkout',
1825 1835 'post_name' => 'wpwbot-app-checkout',
1826 1836 'post_type' => 'page',
@@ -1830,16 +1840,15 @@
1830 1840 //save the id in the database
1831 1841 update_option('wp_chatbot_app_checkout', $app_checkout);
1832 1842 }
1833 1843 //App Order thank you page create
1834 - $existing_thankyou = new WP_Query( array( 'post_type' => 'page', 'name' => 'wpwbot-app-order-thankyou', 'post_status' => 'publish', 'posts_per_page' => 1 ) );
1835 - if ( ! $existing_thankyou->have_posts() ) {
1844 + if (get_page_by_title('wpwBot App Order Thank You') == NULL) {
1836 1845 //post status and options
1837 1846 $thankyou_page = array(
1838 1847 'comment_status' => 'closed',
1839 1848 'ping_status' => 'closed',
1840 1849 'post_author' => get_current_user_id(),
1841 - 'post_date' => gmdate('Y-m-d H:i:s'),
1850 + 'post_date' => date('Y-m-d H:i:s'),
1842 1851 'post_status' => 'publish',
1843 1852 'post_title' => 'wpwBot App Order Thank You',
1844 1853 'post_name' => 'wpwbot-app-order-thankyou',
1845 1854 'post_type' => 'page',
@@ -1850,9 +1859,9 @@
1850 1859 update_option('wp_chatbot_app_order_thankyou', $app_order_thankyou);
1851 1860 }
1852 1861 }
1853 1862 //Keep tracking from App by cookies
1854 - if ( isset( $_GET['from'] ) && sanitize_text_field( wp_unslash( $_GET['from'] ) ) === 'app' ) { // phpcs:ignore WordPress.Security.NonceVerification
1863 + if (isset($_GET['from']) && $_GET['from'] == 'app') {
1855 1864 if (!isset($_COOKIE['from_app'])) {
1856 1865 setcookie('from_app', 'yes', (time() + 3600), '/');
1857 1866 }
1858 1867 }
@@ -1866,9 +1875,9 @@
1866 1875 global $wp;
1867 1876 if (is_checkout() && !empty($wp->query_vars['order-received'])) {
1868 1877 $thanks_page_id = get_option('wp_chatbot_app_order_thankyou');
1869 1878 $thanks_parmanlink = esc_url(get_permalink($thanks_page_id));
1870 - wp_safe_redirect($thanks_parmanlink . '?order_id=' . $order_get_id);
1879 + wp_redirect($thanks_parmanlink . '?order_id=' . $order_get_id);
1871 1880 exit;
1872 1881 }
1873 1882 } else {
1874 1883 remove_action('wpcommerce_thankyou', 'qcld_wb_chatbot__redirect_after_purchase');
@@ -1876,12 +1885,9 @@
1876 1885 }
1877 1886 }
1878 1887
1879 1888 function qcld_choose_random($array){
1880 - if (is_array($array) && !empty($array)) {
1881 - return $array[array_rand($array)];
1882 - }
1883 - return $array;
1889 + return $array[array_rand($array)];
1884 1890 }
1885 1891
1886 1892 //User session count
1887 1893 add_action('wp_ajax_qcld_wb_chatbot_session_count', 'qcld_wb_chatbot_session_count');
@@ -1887,9 +1893,8 @@
1887 1893 add_action('wp_ajax_qcld_wb_chatbot_session_count', 'qcld_wb_chatbot_session_count');
1888 1894 add_action('wp_ajax_nopriv_qcld_wb_chatbot_session_count', 'qcld_wb_chatbot_session_count');
1889 1895 function qcld_wb_chatbot_session_count(){
1890 1896 // Nonce is checked, get the POST data and sign user on
1891 - check_ajax_referer( 'wp_chatbot', 'nonce' );
1892 1897 global $wpdb;
1893 1898 $wpdb->show_errors = true;
1894 1899 $tableuser = $wpdb->prefix.'wpbot_sessions';
1895 1900 $response = array();
@@ -1894,22 +1899,22 @@
1894 1899 $tableuser = $wpdb->prefix.'wpbot_sessions';
1895 1900 $response = array();
1896 1901
1897 1902
1898 - $session_exists = $wpdb->get_row($wpdb->prepare("select * from {$tableuser} where 1 and id = %d",1)); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, PluginCheck.Security.DirectDB.UnescapedDBParameter
1903 + $session_exists = $wpdb->get_row($wpdb->prepare("select * from $tableuser where 1 and id = %d",1)); //DB Call OK, No Caching OK
1899 1904
1900 1905 if(empty($session_exists)){
1901 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
1906 + $wpdb->insert(
1902 1907 $tableuser,
1903 1908 array(
1904 1909 'session' => 1,
1905 1910 )
1906 - );
1911 + ); //DB Call OK, No Caching OK
1907 1912 }else{
1908 1913
1909 1914 $session_id = $session_exists->id;
1910 1915
1911 - $wpdb->update( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1916 + $wpdb->update(
1912 1917 $tableuser,
1913 1918 array(
1914 1919 'session'=>($session_exists->session+1),
1915 1920 ),
@@ -1917,9 +1922,9 @@
1917 1922 array(
1918 1923 '%d',
1919 1924 ),
1920 1925 array('%d')
1921 - );
1926 + ); //DB Call OK, No Caching OK
1922 1927
1923 1928 }
1924 1929
1925 1930 wp_send_json($response);
@@ -1927,9 +1932,9 @@
1927 1932
1928 1933 /* WPBot Chat History Addon check */
1929 1934 function qcld_wpbot_is_active_chat_history(){
1930 1935
1931 - if(function_exists('qcwp_chat_session_menu_fnc') || function_exists('qcwp_chat_session_menu_fnc_free') || function_exists( 'qcpdcs_chat_session_menu_fnc' ) ){
1936 + if(function_exists('qcwp_chat_session_menu_fnc') || function_exists( 'qcpdcs_chat_session_menu_fnc' ) ){
1932 1937 return 1;
1933 1938 }else{
1934 1939 return 0;
1935 1940 }
@@ -1935,73 +1940,18 @@
1935 1940 }
1936 1941
1937 1942 }
1938 1943
1939 -/**
1940 - * Safely sanitize chatbot conversation input.
1941 - *
1942 - * SECURITY FIX (CVE WPBot Stored XSS ≤ 8.6.9):
1943 - * The previous order was: wp_kses() → html_entity_decode() → htmlspecialchars().
1944 - * An attacker could submit entity-encoded payloads (&lt;img onerror=...&gt;) that
1945 - * bypassed wp_kses (which saw inert text), were then decoded back into live markup
1946 - * by html_entity_decode(), and survived into storage and the admin UI.
1947 - *
1948 - * Correct order: html_entity_decode() FIRST → wp_kses() → htmlspecialchars().
1949 - * wp_kses() now sees the real decoded markup and strips forbidden tags/attributes.
1950 - *
1951 - * @param string $data Raw conversation string (already wp_unslash'd by caller).
1952 - * @return string Sanitized, entity-encoded string safe for DB storage.
1953 - */
1954 -function qcld_wpbot_input_validation( $data ) {
1955 - // 1. Decode any entity-encoded HTML so wp_kses sees the real markup.
1956 - $data = html_entity_decode( $data, ENT_QUOTES | ENT_HTML5, 'UTF-8' );
1957 - $data = trim( $data );
1958 - $data = stripslashes( $data );
1959 - // 2. Sanitize with a strict allowlist — NOW operating on decoded markup.
1960 - $data = wp_kses( $data, wpbot_get_safe_conversation_tags() );
1961 - // 3. Re-encode for safe DB storage; admin.js decodes for rendering.
1962 - $data = htmlspecialchars( $data, ENT_QUOTES | ENT_HTML5, 'UTF-8' );
1944 +function qc_wpbot_input_validation( $data ) {
1945 + $data = html_entity_decode($data);
1946 + $data = trim($data);
1947 + $data = stripslashes($data);
1948 + $data = htmlspecialchars($data);
1963 1949 return $data;
1964 1950 }
1951 +add_action('wp_ajax_small_talk_import', 'small_talk_import');
1952 +function small_talk_import(){
1965 1953
1966 -/**
1967 - * Returns the strict HTML allowlist for chatbot conversation content.
1968 - *
1969 - * Critically: no event-handler attributes (onerror, onclick, onload, etc.) are
1970 - * allowed — wp_kses strips any attribute not explicitly listed here.
1971 - * 'img' is intentionally omitted; bot responses that include images should use
1972 - * safe URLs only and can be re-added with only 'src', 'alt', 'class' if needed.
1973 - *
1974 - * @return array<string, array<string, bool>>
1975 - */
1976 -function wpbot_get_safe_conversation_tags() {
1977 - return array(
1978 - 'ul' => array( 'class' => true ),
1979 - 'ol' => array( 'class' => true ),
1980 - 'li' => array( 'class' => true, 'id' => true ),
1981 - 'div' => array( 'class' => true, 'id' => true ),
1982 - 'span' => array( 'class' => true, 'id' => true ),
1983 - 'p' => array( 'class' => true ),
1984 - 'br' => array(),
1985 - 'strong' => array(),
1986 - 'em' => array(),
1987 - 'b' => array(),
1988 - 'i' => array(),
1989 - 'a' => array(
1990 - 'href' => true,
1991 - 'target' => true,
1992 - 'rel' => true,
1993 - 'class' => true,
1994 - ),
1995 - // 'img' intentionally excluded — prevents onerror/onload injection.
1996 - // Add back with only 'src','alt','class' if bot image responses are needed.
1997 - );
1998 -}
1999 -add_action('wp_ajax_qcld_small_talk_import', 'qcld_small_talk_import');
2000 -function qcld_small_talk_import(){
2001 - if ( ! current_user_can( 'manage_options' ) ) {
2002 - wp_die();
2003 - }
2004 1954 global $wpdb;
2005 1955
2006 1956 $table = $wpdb->prefix.'wpbot_response';
2007 1957
@@ -2008,10 +1958,9 @@
2008 1958 $csvFile = file(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . 'small_talk.csv');
2009 1959
2010 1960 foreach ($csvFile as $line) {
2011 1961 $line = str_getcsv($line, ',', '"');
2012 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
2013 - $table, array(
1962 + $wpdb->insert($table, array(
2014 1963 'query' => $line[0],
2015 1964 'keyword' => $line[1],
2016 1965 'response' => $line[2],
2017 1966 'category'=> $line[3],
@@ -2016,17 +1965,16 @@
2016 1965 'response' => $line[2],
2017 1966 'category'=> $line[3],
2018 1967 'intent'=> '',
2019 1968 //'lang'=> 'en_US',
2020 - ));
1969 + )); //DB Call OK, No Caching OK
2021 1970 }
2022 1971
2023 1972 $table2 = $wpdb->prefix.'wpbot_response_category';
2024 1973
2025 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
2026 - $table2, array(
1974 + $wpdb->insert($table2, array(
2027 1975 'name' => 'smalltalk',
2028 - ));
1976 + )); //DB Call OK, No Caching OK
2029 1977
2030 1978 update_option( 'qcld_small_talk_imported', 'yes' );
2031 1979
2032 1980 }
@@ -2034,47 +1982,12 @@
2034 1982 if (!empty($array)) {
2035 1983 foreach ($array as &$value) {
2036 1984 if( !is_array($value) )
2037 1985 // sanitize if value is not an array
2038 - $value = sanitize_text_field( esc_html($value) );
1986 + $value = sanitize_text_field( $value );
2039 1987 else
2040 1988 // go inside this function again
2041 - sanitize_array(esc_html($value));
1989 + $this->sanitize_array($value);
2042 1990 }
2043 1991 }
2044 1992 return $array;
2045 -}
2046 -function qcld_wpbot_meta_tags() {
2047 - echo '<!-- "This site uses ChatBot for WordPress - WPBot from https://www.wpbot.pro/" -->';
2048 -}
2049 -add_action('wp_footer', 'qcld_wpbot_meta_tags', 100);
2050 -
2051 -if ( ! function_exists( 'qcld_change_language_from_center' ) ) {
2052 - add_action( 'wp_ajax_qcld_change_language_from_center', 'qcld_change_language_from_center' );
2053 - add_action( 'wp_ajax_nopriv_qcld_change_language_from_center', 'qcld_change_language_from_center' );
2054 - function qcld_change_language_from_center() {
2055 - if ( ! current_user_can( 'manage_options' ) ) {
2056 - wp_send_json_error( array( 'message' => 'Unauthorized.' ) );
2057 - }
2058 - $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( wp_unslash( $_POST['nonce'] ) ) : '';
2059 - if ( ! wp_verify_nonce( $nonce, 'wp_chatbot' ) ) {
2060 - wp_send_json_error( array( 'message' => 'Invalid nonce.' ) );
2061 - }
2062 - $plugin_path = plugin_dir_path( __FILE__ );
2063 - include $plugin_path . 'includes/admin/settings-fields.php';
2064 - $json_file_path = $plugin_path . 'includes/language-center.json';
2065 -
2066 - $json_string = file_get_contents( $json_file_path );
2067 - if ( isset( $_POST['language'] ) ) {
2068 - $language = sanitize_text_field( wp_unslash( $_POST['language'] ) );
2069 - $language_array= json_decode($json_string)->$language;
2070 - update_option( 'wp_chatbot_language_center_language', $language );
2071 - wp_send_json_success( array( 'message' => true, 'data' => $language_array, 'language' => $language ) );
2072 - } else {
2073 - wp_send_json_error( array( 'message' => 'Language not specified.' ) );
2074 -
2075 - }
2076 - }
2077 -}
2078 -
2079 -// AI Actions Chat Preview
2080 -
1993 +}