PluginProbe
WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services / 6.6.0
WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services v6.6.0
8.7.7 8.7.6 8.7.5 8.7.4 8.7.3 8.7.2 8.7.1 8.7.0 8.6.9 8.6.8 8.6.7 8.6.6 8.6.5 8.6.4 8.6.2 8.6.1 8.6.0 8.5.9 8.5.8 8.5.7 8.5.6 8.5.5 8.5.4 8.5.3 8.5.2 All 533 releases
← All changes | functions.php +115 -388 8.7.56.6.0 View file →
@@ -3,48 +3,11 @@
3 3 * @param $type
4 4 * Display wpwBot Icon ball
5 5 */
6 6 if (!defined('ABSPATH')) exit; // Exit if accessed directly
7 -
8 -
9 -function qcld_custom_search_form( $form ) {
10 - // Add a hidden input to limit search to 'product' post type
11 - if (get_option('wp_chatbot_agent_image') == "custom-agent.png") {
12 - $wp_chatbot_custom_agent_path = get_option('wp_chatbot_custom_agent_path');
13 - } else if (get_option('wp_chatbot_agent_image') != "custom-agent.png") {
14 - $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_agent_image');
15 - } else {
16 - $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . 'custom-agent.png';
17 - }
18 - $hidden_field = '<a class="wp-chatbot qc_wpbot_chat_link" id="wp-chatbot-search-btn" data-search-type="product" data-search-term="" style="max-height: 50px; margin-left: 10px;padding: 0 !important;position: absolute;top: -9px;right: -60px;"><img src="'. esc_url($wp_chatbot_custom_agent_path) .'" alt=""></a>';
19 - $block_content = str_replace( '</form>', $hidden_field . '</form>', $form );
20 - return $block_content;
21 -}
22 -if(get_option('wpbot_enable_on_search') == 1 && (get_option('disable_floating_button') != '1') && get_option('disable_wp_chatbot') != 1 ){
23 - add_filter( 'get_search_form', 'qcld_custom_search_form' );
24 - add_filter( 'render_block_core/search', 'qcld_modify_gutenberg_search_block', 10, 2 );
25 -}
26 -
27 -
28 -function qcld_modify_gutenberg_search_block( $block_content, $block ) {
29 - // Add a hidden input to limit search to 'product' post type
30 - if (get_option('wp_chatbot_agent_image') == "custom-agent.png") {
31 - $wp_chatbot_custom_agent_path = get_option('wp_chatbot_custom_agent_path');
32 - } else if (get_option('wp_chatbot_agent_image') != "custom-agent.png") {
33 - $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_agent_image');
34 - } else {
35 - $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . 'custom-agent.png';
36 - }
37 - $hidden_field = '<button type="button" class="wp-chatbot qc_wpbot_chat_link" id="wp-chatbot-search-btn" data-search-type="product" data-search-term="" style="max-height: 50px; margin-left: 10px;padding: 0 !important"><img src="'. esc_url($wp_chatbot_custom_agent_path) .'" alt=""></button>';
38 - // Inject the hidden field before the closing </form> tag
39 - $block_content = str_replace( '</div></form>', $hidden_field . '</div></form>', $block_content );
40 - return $block_content;
41 -}
42 -if(get_option('disable_floating_button') != '1'){
43 - add_action('wp_footer', 'wp_chatbot_load_footer_html');
44 -}
45 -add_action( 'admin_footer', 'qcld_style_for_hide_iframe');
46 -function qcld_style_for_hide_iframe(){
7 +add_action('wp_footer', 'wp_chatbot_load_footer_html');
8 +add_action( 'admin_footer', 'qc_style_for_hide_iframe');
9 +function qc_style_for_hide_iframe(){
47 10 ?>
48 11 <script>
49 12 jQuery( document ).ready(function() {
50 13 setInterval(function(){
@@ -58,62 +21,8 @@
58 21 });
59 22 </script>
60 23 <?php
61 24 }
62 -/**
63 - * Extract a YouTube video ID from common URL formats.
64 - *
65 - * @param string $url YouTube watch, embed, short, or youtu.be URL.
66 - * @return string Video ID or empty string.
67 - */
68 -if ( ! function_exists( 'qcld_wpbot_extract_youtube_id' ) ) {
69 - function qcld_wpbot_extract_youtube_id( $url ) {
70 - $url = trim( (string) $url );
71 - if ( $url === '' ) {
72 - return '';
73 - }
74 -
75 - if ( preg_match( '/(?:youtube\.com\/(?:embed\/|shorts\/|live\/|watch\?(?:.*&)?v=)|youtu\.be\/)([A-Za-z0-9_-]{11})/', $url, $matches ) ) {
76 - return $matches[1];
77 - }
78 -
79 - $path = (string) wp_parse_url( $url, PHP_URL_PATH );
80 - $base = basename( $path );
81 - if ( preg_match( '/^[A-Za-z0-9_-]{11}$/', $base ) ) {
82 - return $base;
83 - }
84 -
85 - return '';
86 - }
87 -}
88 -if ( ! function_exists( 'qcld_wpbot_youtube_icon_embed_src' ) ) {
89 - function qcld_wpbot_youtube_icon_embed_src( $url ) {
90 - $video_id = qcld_wpbot_extract_youtube_id( $url );
91 - if ( $video_id === '' ) {
92 - return '';
93 - }
94 -
95 - return add_query_arg(
96 - array(
97 - 'autoplay' => '1',
98 - 'mute' => '1',
99 - 'loop' => '1',
100 - 'playlist' => $video_id,
101 - 'controls' => '0',
102 - 'showinfo' => '0',
103 - 'rel' => '0',
104 - 'fs' => '0',
105 - 'iv_load_policy' => '3',
106 - 'cc_load_policy' => '0',
107 - 'disablekb' => '1',
108 - 'playsinline' => '1',
109 - 'modestbranding' => '1',
110 - 'color' => 'white',
111 - ),
112 - 'https://www.youtube.com/embed/' . rawurlencode( $video_id )
113 - );
114 - }
115 -}
116 25 function wp_chatbot_load_footer_html(){
117 26 if ( get_option('disable_wp_chatbot') != 1 && wp_chatbot_load_controlling() === true) {
118 27
119 28 ?>
@@ -118,10 +27,11 @@
118 27
119 28 ?>
120 29 <style>
121 30 <?php if(get_option('wp_chatbot_custom_css')!="") {
122 -
123 - echo wp_strip_all_tags( get_option('wp_chatbot_custom_css') );// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
31 + //Sanitization to be checked
32 + // phpcs:ignore
33 + echo sanitize_text_field(get_option('wp_chatbot_custom_css'));
124 34 }
125 35 ?>
126 36 </style>
127 37
@@ -133,27 +43,10 @@
133 43 }
134 44 ?>
135 45 <style>
136 46 .wp-chatbot-container {
137 - background-color: #eceef3 !important;
138 47 background-image: url(<?php echo esc_url($qcld_wb_chatbot_board_bg_path); ?>) !important;
139 - background-size: cover !important;
140 - background-position: center !important;
141 - background-repeat: no-repeat !important;
142 48 }
143 - .wp-chatbot-template-01 #wp-chatbot-board-container,
144 - .wp-chatbot-template-01 .wp-chatbot-board-container {
145 - background-color: #eceef3 !important;
146 - background-image: none !important;
147 - }
148 - .wp-chatbot-template-01 #wp-chatbot-board-container::before,
149 - .wp-chatbot-template-01 .wp-chatbot-board-container::before {
150 - background-color: #eceef3 !important;
151 - background-image: url(<?php echo esc_url($qcld_wb_chatbot_board_bg_path); ?>) !important;
152 - background-size: cover !important;
153 - background-position: center !important;
154 - background-repeat: no-repeat !important;
155 - }
156 49 </style>
157 50 <?php }
158 51 $wp_chatbot_enable_rtl = "";
159 52 if (get_option('enable_wp_chatbot_rtl') == '1') {
@@ -163,33 +56,33 @@
163 56 // if (get_option('enable_wp_chatbot_mobile_full_screen')==1) {
164 57 $wp_chatbot_enable_mobile_screen .= "wp-chatbot-mobile-full-screen";
165 58 // }
166 59 ?>
167 - <div id="wp-chatbot-chat-container" class="<?php echo esc_attr($wp_chatbot_enable_rtl .' '.$wp_chatbot_enable_mobile_screen); ?>" style="<?php if(get_option('disable_floating_button') == '1'){ echo 'display:none';} ?>">
60 + <div id="wp-chatbot-chat-container" class="<?php echo esc_attr($wp_chatbot_enable_rtl .' '.$wp_chatbot_enable_mobile_screen); ?>">
168 61 <div id="wp-chatbot-integration-container">
169 62 <div class="wp-chatbot-integration-button-container">
170 63 <?php if (get_option('enable_wp_chatbot_skype_floating_icon') == 1) { ?>
171 64 <a href="skype:<?php echo esc_attr(get_option('enable_wp_chatbot_skype_id')); ?>?chat"><span
172 - class="inetegration-skype-btn" title="<?php esc_attr_e('Skype', 'chatbot'); ?>"> </span></a>
65 + class="inetegration-skype-btn" title="<?php esc_attr_e('Skype', 'wpchatbot'); ?>"> </span></a>
173 66 <?php } ?>
174 67 <?php if (get_option('enable_wp_chatbot_floating_whats') == 1) { ?>
175 68 <a href="<?php echo esc_url('https://api.whatsapp.com/send?phone=' . get_option('qlcd_wp_chatbot_whats_num')); ?>"
176 69 target="_blank"><span class="intergration-whats"
177 - title="<?php esc_html_e('WhatsApp', 'chatbot'); ?>"></span></a>
70 + title="<?php esc_html_e('WhatsApp', 'wpchatbot'); ?>"></span></a>
178 71 <?php } ?>
179 72 <?php if (get_option('enable_wp_chatbot_floating_viber') == 1) { ?>
180 73 <a href="<?php echo esc_url('https://live.viber.com/#/' . get_option('qlcd_wp_chatbot_viber_acc')); ?>"
181 74 target="_blank"><span class="intergration-viber"
182 - title="<?php esc_html_e('Viber', 'chatbot'); ?>"></span></a>
75 + title="<?php esc_html_e('Viber', 'wpchatbot'); ?>"></span></a>
183 76 <?php } ?>
184 77 <?php if (get_option('enable_wp_chatbot_floating_phone') == 1 && get_option('qlcd_wp_chatbot_phone') != "") { ?>
185 78 <a href="tel:<?php echo esc_attr(get_option('qlcd_wp_chatbot_phone')); ?>"><span
186 79 class="intergration-phone"
187 - title="<?php esc_html_e('Phone', 'chatbot'); ?>"> </span></a>
80 + title="<?php esc_html_e('Phone', 'wpchatbot'); ?>"> </span></a>
188 81 <?php } ?>
189 82 <?php if (get_option('enable_wp_chatbot_floating_link') == 1 && get_option('qlcd_wp_chatbot_weblink') != "") { ?>
190 83 <a href="<?php echo esc_url(get_option('qlcd_wp_chatbot_weblink')); ?>" target="_blank"><span
191 - class="intergration-weblink" title="<?php esc_html_e('Web Link', 'chatbot'); ?>"></span></a>
84 + class="intergration-weblink" title="<?php esc_html_e('Web Link', 'wpchatbot'); ?>"></span></a>
192 85 <?php } ?>
193 86 </div>
194 87 </div>
195 88 <?php
@@ -202,9 +95,9 @@
202 95 }
203 96 if (file_exists(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/template.php')) {
204 97 require_once(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . '/templates/' . $qcld_wb_chatbot_theme . '/template.php');
205 98 } else {
206 - echo "<h2>" . esc_html__('No wpWBot Theme Found!', 'chatbot') . "</h2>";
99 + echo "<h2>" . esc_html__('No wpWBot Theme Found!', 'wpchatbot') . "</h2>";
207 100 }
208 101 ?>
209 102 <?php
210 103 if (get_option('disable_wp_chatbot_notification') != 1) {
@@ -211,9 +104,9 @@
211 104 ?>
212 105 <div id="wp-chatbot-notification-container" class="wp-chatbot-notification-container">
213 106 <div class="wp-chatbot-notification-controller">
214 107 <span class="wp-chatbot-notification-close">
215 - <?php esc_html_e('X', 'chatbot'); ?>
108 + <?php esc_html_e('X', 'wpchatbot'); ?>
216 109 </span>
217 110 </div>
218 111 <?php
219 112 $testingTip="";
@@ -226,9 +119,9 @@
226 119 }
227 120 ?>
228 121 <div class="wp-chatbot-notification-agent-profile">
229 122 <div class="wp-chatbot-notification-widget-avatar" ><img
230 - src="<?php echo esc_url($wp_chatbot_custom_agent_path); ?>" alt=""></div>
123 + src="<?php echo esc_attr($wp_chatbot_custom_agent_path); ?>" alt=""></div>
231 124 <div class="wp-chatbot-notification-welcome"><?php echo wp_kses_post(wpb_randmom_message_handle(maybe_unserialize(get_option('qlcd_wp_chatbot_welcome')))) . ' <strong>' . esc_html(get_option('qlcd_wp_chatbot_host')) . '</strong>'; ?></div>
232 125 </div>
233 126 <?php
234 127 //update_option('qlcd_wp_chatbot_notifications','Welcome to WpBot');
@@ -251,72 +144,14 @@
251 144 $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_icon');
252 145 } else {
253 146 $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . 'custom.png';
254 147 }
255 - $_wpbot_icon_video = get_option('wp_chatbot_icon_video', '');
256 - $_wpbot_video_is_youtube = ( strpos( $_wpbot_icon_video, 'youtube.com' ) !== false || strpos( $_wpbot_icon_video, 'youtu.be' ) !== false );
257 - $_wpbot_youtube_embed_src = $_wpbot_video_is_youtube ? qcld_wpbot_youtube_icon_embed_src( $_wpbot_icon_video ) : '';
258 - $_wpbot_video_delay_ms = absint( get_option( 'wp_chatbot_icon_video_delay', 0 ) ) * 1000;
259 -
260 - $wp_chatbot_ball_is_youtube = ($_wpbot_icon_video !== '' && (strpos($_wpbot_icon_video, 'youtube.com') !== false || strpos($_wpbot_icon_video, 'youtu.be') !== false));
261 - $wp_chatbot_ball_is_video = ($_wpbot_icon_video !== '' && !$wp_chatbot_ball_is_youtube);
262 - $wp_chatbot_ball_has_video = ($wp_chatbot_ball_is_youtube || $wp_chatbot_ball_is_video);
263 148 ?>
264 149 <img src="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>"
265 - alt="wpChatIcon" qcld_agent="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>"
266 - id="wp-chatbot-ball-icon-img"
267 - <?php if ($wp_chatbot_ball_has_video) { echo 'style="display:none;"'; } ?> >
268 - <?php if ( $_wpbot_icon_video !== '' ) : ?>
269 - <?php if ( $_wpbot_video_is_youtube && $_wpbot_youtube_embed_src !== '' ) : ?>
270 - <iframe class="wpbot-icon-video" src="<?php echo $_wpbot_video_delay_ms > 0 ? 'about:blank' : esc_url( $_wpbot_youtube_embed_src ); ?>" data-wpbot-yt-src="<?php echo esc_url( $_wpbot_youtube_embed_src ); ?>" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture"></iframe>
271 - <?php elseif ( ! $_wpbot_video_is_youtube ) : ?>
272 - <video class="wpbot-icon-video" src="<?php echo esc_url( $_wpbot_icon_video ); ?>" autoplay muted loop playsinline preload="auto"></video>
273 - <?php endif; ?>
274 - <?php endif; ?>
150 + alt="wpChatIcon" qcld_agent="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>" >
151 +
275 152 </div>
276 -
277 153 </div>
278 - <?php
279 - if ( $_wpbot_icon_video !== '' ) :
280 - ?>
281 - <script>
282 - (function(){
283 - var wpbotDelay = <?php echo (int) $_wpbot_video_delay_ms; ?>;
284 - function wpbotForcePlay(){
285 - var v = document.querySelector('#wp-chatbot-ball video.wpbot-icon-video');
286 - if( v ){
287 - v.muted = true;
288 - v.volume = 0;
289 - v.loop = true;
290 - var tries = 0, maxTries = 30;
291 - var timer = setInterval(function(){
292 - tries++;
293 - v.play().then(function(){ clearInterval(timer); }).catch(function(){});
294 - if( tries >= maxTries ) clearInterval(timer);
295 - }, 300);
296 - }
297 - var yt = document.querySelector('#wp-chatbot-ball iframe.wpbot-icon-video');
298 - if( yt ){
299 - var ytSrc = yt.getAttribute('data-wpbot-yt-src');
300 - if( ytSrc && ( !yt.getAttribute('src') || yt.getAttribute('src') === 'about:blank' || yt.getAttribute('src').indexOf('autoplay=1') === -1 ) ){
301 - yt.setAttribute('src', ytSrc);
302 - }
303 - }
304 - }
305 - function wpbotDelayedPlay(){
306 - setTimeout(wpbotForcePlay, wpbotDelay);
307 - }
308 - if( document.readyState === 'loading' ){
309 - document.addEventListener('DOMContentLoaded', wpbotDelayedPlay);
310 - } else {
311 - wpbotDelayedPlay();
312 - }
313 - window.addEventListener('load', function(){
314 - setTimeout(wpbotForcePlay, wpbotDelay);
315 - });
316 - })();
317 - </script>
318 - <?php endif; ?>
319 154 <?php
320 155 $fb_app_id = get_option('qlcd_wp_chatbot_fb_app_id');
321 156 $fb_page_id = get_option('qlcd_wp_chatbot_fb_page_id');
322 157 $fb_mgs_color = get_option('qlcd_wp_chatbot_fb_color') != '' ? get_option('qlcd_wp_chatbot_fb_color') : '#0084ff';
@@ -359,11 +194,11 @@
359 194 </div>
360 195
361 196 <?php
362 197
363 - if ( get_transient( 'qcld_bot_clear_cache' ) ) {
198 + if ( get_transient( 'bot_clear_cache' ) ) {
364 199 echo '<script type="text/javascript">var wpbot_clear_cache = 1 </script>';
365 - delete_transient( 'qcld_bot_clear_cache' );
200 + delete_transient( 'bot_clear_cache' );
366 201 }
367 202
368 203 }else{
369 204 ?>
@@ -433,9 +268,9 @@
433 268 return $wp_chatbot_load;
434 269 }
435 270 //checking Devices
436 271 function wp_chatbot_is_mobile(){
437 - $useragent = isset( $_SERVER['HTTP_USER_AGENT'] ) ? $_SERVER['HTTP_USER_AGENT'] : '';
272 + $useragent = $_SERVER['HTTP_USER_AGENT'];
438 273 if (preg_match('/(android|bb\d+|meego).+mobile|avantgo|bada\/|blackberry|blazer|compal|elaine|fennec|hiptop|iemobile|ip(hone|od)|iris|kindle|lge |maemo|midp|mmp|netfront|opera m(ob|in)i|palm( os)?|phone|p(ixi|re)\/|plucker|pocket|psp|series(4|6)0|symbian|treo|up\.(browser|link)|vodafone|wap|windows (ce|phone)|xda|xiino/i', $useragent) || preg_match('/1207|6310|6590|3gso|4thp|50[1-6]i|770s|802s|a wa|abac|ac(er|oo|s\-)|ai(ko|rn)|al(av|ca|co)|amoi|an(ex|ny|yw)|aptu|ar(ch|go)|as(te|us)|attw|au(di|\-m|r |s )|avan|be(ck|ll|nq)|bi(lb|rd)|bl(ac|az)|br(e|v)w|bumb|bw\-(n|u)|c55\/|capi|ccwa|cdm\-|cell|chtm|cldc|cmd\-|co(mp|nd)|craw|da(it|ll|ng)|dbte|dc\-s|devi|dica|dmob|do(c|p)o|ds(12|\-d)|el(49|ai)|em(l2|ul)|er(ic|k0)|esl8|ez([4-7]0|os|wa|ze)|fetc|fly(\-|_)|g1 u|g560|gene|gf\-5|g\-mo|go(\.w|od)|gr(ad|un)|haie|hcit|hd\-(m|p|t)|hei\-|hi(pt|ta)|hp( i|ip)|hs\-c|ht(c(\-| |_|a|g|p|s|t)|tp)|hu(aw|tc)|i\-(20|go|ma)|i230|iac( |\-|\/)|ibro|idea|ig01|ikom|im1k|inno|ipaq|iris|ja(t|v)a|jbro|jemu|jigs|kddi|keji|kgt( |\/)|klon|kpt |kwc\-|kyo(c|k)|le(no|xi)|lg( g|\/(k|l|u)|50|54|\-[a-w])|libw|lynx|m1\-w|m3ga|m50\/|ma(te|ui|xo)|mc(01|21|ca)|m\-cr|me(rc|ri)|mi(o8|oa|ts)|mmef|mo(01|02|bi|de|do|t(\-| |o|v)|zz)|mt(50|p1|v )|mwbp|mywa|n10[0-2]|n20[2-3]|n30(0|2)|n50(0|2|5)|n7(0(0|1)|10)|ne((c|m)\-|on|tf|wf|wg|wt)|nok(6|i)|nzph|o2im|op(ti|wv)|oran|owg1|p800|pan(a|d|t)|pdxg|pg(13|\-([1-8]|c))|phil|pire|pl(ay|uc)|pn\-2|po(ck|rt|se)|prox|psio|pt\-g|qa\-a|qc(07|12|21|32|60|\-[2-7]|i\-)|qtek|r380|r600|raks|rim9|ro(ve|zo)|s55\/|sa(ge|ma|mm|ms|ny|va)|sc(01|h\-|oo|p\-)|sdk\/|se(c(\-|0|1)|47|mc|nd|ri)|sgh\-|shar|sie(\-|m)|sk\-0|sl(45|id)|sm(al|ar|b3|it|t5)|so(ft|ny)|sp(01|h\-|v\-|v )|sy(01|mb)|t2(18|50)|t6(00|10|18)|ta(gt|lk)|tcl\-|tdg\-|tel(i|m)|tim\-|t\-mo|to(pl|sh)|ts(70|m\-|m3|m5)|tx\-9|up(\.b|g1|si)|utst|v400|v750|veri|vi(rg|te)|vk(40|5[0-3]|\-v)|vm40|voda|vulc|vx(52|53|60|61|70|80|81|83|85|98)|w3c(\-| )|webc|whit|wi(g |nc|nw)|wmlb|wonu|x700|yas\-|your|zeto|zte\-/i', substr($useragent, 0, 4))) {
439 274 return true;
440 275 } else {
441 276 return false;
@@ -442,10 +277,10 @@
442 277 }
443 278 }
444 279 //Checking wpwbot opening hour
445 280 function wp_chatbot_check_opening_hours(){
446 - $curent_day=strtolower(gmdate('l',strtotime(current_time( 'mysql' ))));
447 - $current_time=gmdate('H:i',strtotime(current_time( 'mysql')));
281 + $curent_day=strtolower(date('l',strtotime(current_time( 'mysql' ))));
282 + $current_time=date('H:i',strtotime(current_time( 'mysql')));
448 283 $is_wpwbot_open =false;
449 284 if(get_option('wpwbot_hours')) {
450 285 $wpwbot_times = wp_kses_post(unserialize(get_option('wpwbot_hours')));
451 286 if (isset($wpwbot_times[$curent_day])) {
@@ -467,16 +302,9 @@
467 302 */
468 303 add_action('wp_ajax_qcld_wb_chatbot_keyword', 'qcld_wb_chatbot_keyword');
469 304 add_action('wp_ajax_nopriv_qcld_wb_chatbot_keyword', 'qcld_wb_chatbot_keyword');
470 305 function qcld_wb_chatbot_keyword(){
471 - // Verify nonce for security
472 - $nonce = isset($_POST['security']) ? sanitize_text_field(wp_unslash($_POST['security'])) : (isset($_POST['nonce']) ? sanitize_text_field(wp_unslash($_POST['nonce'])) : '');
473 - if ( ! wp_verify_nonce( $nonce, 'wp_chatbot' ) && ! wp_verify_nonce( $nonce, 'qcsecretbotnonceval123qc' ) ) {
474 - wp_send_json_error( array( 'status' => 'fail', 'message' => 'Security check failed.' ) );
475 - wp_die();
476 - }
477 -
478 - $keyword = sanitize_text_field(wp_unslash($_POST['keyword']));
306 + $keyword = sanitize_text_field($_POST['keyword']);
479 307 $product_per_page = get_option('qlcd_wp_chatbot_ppp') != '' ? get_option('qlcd_wp_chatbot_ppp') : 10;
480 308 if (get_option('qlcd_wp_chatbot_search_option') == 'standard') {
481 309 $product_orderby = sanitize_text_field(get_option('qlcd_wp_chatbot_product_orderby') != '' ? get_option('qlcd_wp_chatbot_product_orderby') : 'title');
482 310 $product_order = sanitize_text_field(get_option('qlcd_wp_chatbot_product_order') != '' ? get_option('qlcd_wp_chatbot_product_order') : 'ASC');
@@ -522,9 +350,9 @@
522 350 endwhile;
523 351 wp_reset_postdata();
524 352 $html .= '</ul>';
525 353 if ($total_product_num > $product_per_page && $product_per_page > 0 ) {
526 - $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . esc_attr($keyword) . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
354 + $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . $keyword . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
527 355 }
528 356 }
529 357 $html .= '</div>';
530 358 } else if (get_option('qlcd_wp_chatbot_search_option') == 'advanced') {
@@ -552,9 +380,9 @@
552 380 }
553 381 }
554 382 $html .= '</ul>';
555 383 if ($total_product_num > $product_per_page && $product_per_page > 0) {
556 - $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . esc_attr($more_product_ids) . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
384 + $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . $more_product_ids . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
557 385 }
558 386 }
559 387 $html .= '</div>';
560 388 }
@@ -569,15 +397,16 @@
569 397 add_action('wp_ajax_nopriv_qcld_wb_chatbot_category', 'qcld_wb_chatbot_category');
570 398 function qcld_wb_chatbot_category(){
571 399 $category_type="common";
572 400 if (get_option('wp_chatbot_show_parent_category') != "") {
573 - $terms = get_terms( array( 'taxonomy' => 'product_cat', 'parent' => 0, 'hide_empty' => true, 'fields' => 'all' ) );
401 + $terms = get_terms('product_cat', array('parent' => 0, 'hide_empty' => true, 'fields' => 'all'));
402 +
574 403 } else {
575 - $terms = get_terms( array( 'taxonomy' => 'product_cat', 'hide_empty' => true, 'fields' => 'all' ) );
404 + $terms = get_terms('product_cat', array('hide_empty' => true, 'fields' => 'all'));
576 405 }
577 406 $html = "";
578 407 foreach ($terms as $term) {
579 - $child_terms=get_terms( array( 'taxonomy' => 'product_cat', 'parent' => $term->term_id, 'hide_empty' => true, 'fields' => 'all' ) );
408 + $child_terms=get_terms('product_cat', array('parent' => $term->term_id, 'hide_empty' => true, 'fields' => 'all'));
580 409 if(get_option('wp_chatbot_show_sub_category')==1 && count($child_terms) >0){
581 410 $category_type="hasChilds";
582 411 }
583 412 $html .= '<span class="qcld-chatbot-product-category" data-category-type="' . $category_type . '" data-category-slug="' . $term->slug . '" data-category-id="' . $term->term_id . '">' . $term->name . '</span>';
@@ -590,10 +419,10 @@
590 419 */
591 420 add_action('wp_ajax_qcld_wb_chatbot_sub_category', 'qcld_wb_chatbot_sub_category');
592 421 add_action('wp_ajax_nopriv_qcld_wb_chatbot_sub_category', 'qcld_wb_chatbot_sub_category');
593 422 function qcld_wb_chatbot_sub_category(){
594 - $parent_id = intval( wp_unslash( $_POST['parent_id'] ) );
595 - $terms = get_terms( array( 'taxonomy' => 'product_cat', 'parent' => $parent_id, 'hide_empty' => true, 'fields' => 'all' ) );
423 + $parent_id = stripslashes($_POST['parent_id']);
424 + $terms = get_terms('product_cat', array('parent' => $parent_id, 'hide_empty' => true, 'fields' => 'all'));
596 425 $html = "";
597 426 foreach ($terms as $term) {
598 427 $html .= '<span class="qcld-chatbot-product-category" data-category-type="common" data-category-slug="' . $term->slug . '" data-category-id="' . $term->term_id . '">' . $term->name . '</span>';
599 428 }
@@ -605,9 +434,9 @@
605 434 */
606 435 add_action('wp_ajax_qcld_wb_chatbot_category_products', 'qcld_wb_chatbot_category_products');
607 436 add_action('wp_ajax_nopriv_qcld_wb_chatbot_category_products', 'qcld_wb_chatbot_category_products');
608 437 function qcld_wb_chatbot_category_products(){
609 - $category_id = intval( wp_unslash( $_POST['category'] ) );
438 + $category_id = stripslashes($_POST['category']);
610 439 $product_per_page = sanitize_text_field(get_option('qlcd_wp_chatbot_ppp') != '' ? get_option('qlcd_wp_chatbot_ppp') : 10);
611 440 $product_orderby = sanitize_text_field(get_option('qlcd_wp_chatbot_product_orderby') != '' ? get_option('qlcd_wp_chatbot_product_orderby') : 'title');
612 441 $product_order = sanitize_text_field(get_option('qlcd_wp_chatbot_product_order') != '' ? get_option('qlcd_wp_chatbot_product_order') : 'ASC');
613 442 //Merging all query together.
@@ -844,11 +673,11 @@
844 673 //load more
845 674 add_action('wp_ajax_qcld_wb_chatbot_load_more', 'qcld_wb_chatbot_load_more');
846 675 add_action('wp_ajax_nopriv_qcld_wb_chatbot_load_more', 'qcld_wb_chatbot_load_more');
847 676 function qcld_wb_chatbot_load_more(){
848 - $offset = intval( wp_unslash( $_POST['offset'] ) );
849 - $search_type = sanitize_text_field( wp_unslash( $_POST['search_type'] ) );
850 - $search_term = sanitize_text_field( wp_unslash( $_POST['search_term'] ) );
677 + $offset = stripslashes($_POST['offset']);
678 + $search_type = stripslashes($_POST['search_type']);
679 + $search_term = stripslashes($_POST['search_term']);
851 680 $product_per_page = sanitize_text_field(get_option('qlcd_wp_chatbot_ppp') != '' ? get_option('qlcd_wp_chatbot_ppp') : 10);
852 681 $product_orderby = sanitize_text_field(get_option('qlcd_wp_chatbot_product_orderby') != '' ? get_option('qlcd_wp_chatbot_product_orderby') : 'title');
853 682 $product_order = sanitize_text_field(get_option('qlcd_wp_chatbot_product_order') != '' ? get_option('qlcd_wp_chatbot_product_order') : 'ASC');
854 683 $next_offset = intval($product_per_page + $offset);
@@ -979,9 +808,9 @@
979 808 //product details
980 809 add_action('wp_ajax_qcld_wb_chatbot_product_details', 'qcld_wb_chatbot_product_details');
981 810 add_action('wp_ajax_nopriv_qcld_wb_chatbot_product_details', 'qcld_wb_chatbot_product_details');
982 811 function qcld_wb_chatbot_product_details(){
983 - $product_id = intval( wp_unslash( $_POST['wp_chatbot_pid'] ) );
812 + $product_id = stripslashes($_POST['wp_chatbot_pid']);
984 813 //Tracking product view from chat board
985 814 wp_chatbot_view_track_product_by_id($product_id);
986 815 //wpcommerce product factory
987 816 $wc_pf = new WC_Product_Factory();
@@ -1009,9 +838,9 @@
1009 838 }
1010 839 }
1011 840 $product_image .= '</ul></div>';
1012 841 $product_price = '<p class="wp-chatbot-product-price" id="wp-chatbot-product-price">' . $product->get_price_html() . '</p>';
1013 - $product_sku = '<p class="wp-chatbot-product-sku"> ' . __('SKU', 'chatbot') . ' : ' . $product->get_sku() . '</p>';
842 + $product_sku = '<p class="wp-chatbot-product-sku"> ' . __('SKU', 'wpchatbot') . ' : ' . $product->get_sku() . '</p>';
1014 843 //if ( $product->is_in_stock() || $product->is_purchasable() )
1015 844 //Handle variable product start
1016 845 $variations = "";
1017 846 $add_cart_button = "";
@@ -1054,11 +883,10 @@
1054 883 $variations .= '<label for="' . sanitize_title($name) . '">' . $title . '</label>';
1055 884 $variations .= '<select id="' . esc_attr(sanitize_title($name)) . '" name="attribute_' . sanitize_title($name) . '" data-attribute_name="attribute_' . sanitize_title($name) . '" class="each_attribute">';
1056 885 $variations .= '<option value="">' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_choose_option')))) . '</option>';
1057 886 foreach ($values as $value) {
1058 - $attr_key = 'attribute_' . sanitize_title( $name );
1059 - if ( isset( $_REQUEST[ $attr_key ] ) ) { // phpcs:ignore WordPress.Security.NonceVerification
1060 - $selected_value = sanitize_text_field( wp_unslash( $_REQUEST[ $attr_key ] ) );
887 + if (isset($_REQUEST['attribute_' . sanitize_title($name)])) {
888 + $selected_value = $_REQUEST['attribute_' . sanitize_title($name)];
1061 889 } else {
1062 890 $selected_value = '';
1063 891 }
1064 892 $variations .= '<option value="' . esc_attr(strtolower($value)) . '"' . selected($selected_value, $value, false) . '>' . apply_filters('wpcommerce_variation_option_name', $value) . '</option>';
@@ -1079,15 +907,15 @@
1079 907 $response = array('title' => $product_title, 'description' => $product_desc, 'image' => $product_image, 'price' => $product_price, 'sku' => $product_sku, 'quantity' => $product_quantity, 'buttton' => $add_cart_button, 'variation' => $variations, 'type' => $product_type, 'debug' => $debug);
1080 908 wp_send_json($response);
1081 909 }
1082 910 //Add to cart for variable product.
1083 -add_action('wp_ajax_qcld_variable_add_to_cart', 'qcld_variable_add_to_cart');
1084 -add_action('wp_ajax_nopriv_qcld_variable_add_to_cart', 'qcld_variable_add_to_cart');
1085 -function qcld_variable_add_to_cart(){
1086 - $product_id = intval( wp_unslash( $_POST['p_id'] ) );
1087 - $quantity = intval( wp_unslash( $_POST['quantity'] ) );
1088 - $variations_id = intval( wp_unslash( $_POST['variations_id'] ) );
1089 - $attrs = isset( $_POST['attributes'] ) ? array_map( 'sanitize_text_field', wp_unslash( (array) $_POST['attributes'] ) ) : array();
911 +add_action('wp_ajax_variable_add_to_cart', 'qcld_wb_chatbot_variable_add_to_cart');
912 +add_action('wp_ajax_nopriv_variable_add_to_cart', 'qcld_wb_chatbot_variable_add_to_cart');
913 +function qcld_wb_chatbot_variable_add_to_cart(){
914 + $product_id = stripslashes($_POST['p_id']);
915 + $quantity = stripslashes($_POST['quantity']);
916 + $variations_id = stripslashes($_POST['variations_id']);
917 + $attrs = stripslashes($_POST['attributes']);
1090 918 //echo wp_send_json(array('p_id'=>$product_id,'qnty'=>$quantity,'id'=>$variations_id,'att'=>$attrs));
1091 919 $attributes = array();
1092 920 foreach ($attrs as $attr) {
1093 921 $single = explode("#", $attr);
@@ -1107,10 +935,10 @@
1107 935 //Add to cart for simple product.
1108 936 add_action('wp_ajax_qcld_wb_chatbot_add_to_cart', 'qcld_wb_chatbot_add_to_cart');
1109 937 add_action('wp_ajax_nopriv_qcld_wb_chatbot_add_to_cart', 'qcld_wb_chatbot_add_to_cart');
1110 938 function qcld_wb_chatbot_add_to_cart(){
1111 - $product_id = intval( wp_unslash( $_POST['product_id'] ) );
1112 - $product_quantity = intval( wp_unslash( $_POST['quantity'] ) );
939 + $product_id = stripslashes($_POST['product_id']);
940 + $product_quantity = stripslashes($_POST['quantity']);
1113 941 global $wpcommerce;
1114 942 $result = $wpcommerce->cart->add_to_cart($product_id, $product_quantity);
1115 943 if ($result != false) {
1116 944 wp_send_json('simple');
@@ -1121,19 +949,15 @@
1121 949 //Support part
1122 950 add_action('wp_ajax_qcld_wb_chatbot_support_email', 'qcld_wb_chatbot_support_email');
1123 951 add_action('wp_ajax_nopriv_qcld_wb_chatbot_support_email', 'qcld_wb_chatbot_support_email');
1124 952 function qcld_wb_chatbot_support_email(){
1125 - $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( wp_unslash( $_POST['nonce'] ) ) : '';
1126 - if ( ! wp_verify_nonce( $nonce, 'qcsecretbotnonceval123qc' ) ) {
1127 - wp_send_json_error( array( 'error' => esc_html__( 'Error: Invalid nonce verification.', 'chatbot' ) ) );
1128 - }
1129 - $name = trim(sanitize_text_field(wp_unslash($_POST['name'])));
1130 - $email = sanitize_email(wp_unslash($_POST['email']));
1131 - $message = sanitize_text_field(wp_unslash($_POST['message']));
953 + $name = trim(sanitize_text_field($_POST['name']));
954 + $email = sanitize_email($_POST['email']);
955 + $message = sanitize_text_field($_POST['message']);
1132 956 $subject = sanitize_text_field(get_option('qlcd_wp_chatbot_email_sub') != '' ? get_option('qlcd_wp_chatbot_email_sub') : 'Support Email from wpWBot by Client');
1133 957 //Extract Domain
1134 958 $url = get_site_url();
1135 - $url = wp_parse_url($url);
959 + $url = parse_url($url);
1136 960 $domain = $url['host'];
1137 961 //$admin_email = "admin@" . $domain;
1138 962 $admin_email = sanitize_email(get_option('admin_email'));
1139 963 $toEmail = sanitize_email(get_option('qlcd_wp_chatbot_admin_email') != '' ? get_option('qlcd_wp_chatbot_admin_email') : $admin_email);
@@ -1143,8 +967,9 @@
1143 967 $fromEmail = get_option('qlcd_wp_chatbot_from_email');
1144 968 }else{
1145 969 $fromEmail = "wordpress@" . $domain;
1146 970 }
971 +
1147 972 //Starting messaging and status.
1148 973 $response['status'] = 'fail';
1149 974 $response['message'] = str_replace('\\', '',wp_kses_post(get_option('qlcd_wp_chatbot_email_fail')));
1150 975 if (filter_var($email, FILTER_VALIDATE_EMAIL) === false) {
@@ -1152,14 +977,14 @@
1152 977 $response['status'] = 'fail';
1153 978 } else {
1154 979 //build email body
1155 980 $bodyContent = "";
1156 - $bodyContent .= '<p><strong>' . __('Support Request Details', 'chatbot') . ':</strong></p><hr>';
1157 - $bodyContent .= '<p>' . __('Name', 'chatbot') . ' : ' . $name . '</p>';
1158 - $bodyContent .= '<p>' . __('Email', 'chatbot') . ' : ' . $email . '</p>';
1159 - $bodyContent .= '<p>' . __('Subject', 'chatbot') . ' : ' . $subject . '</p>';
1160 - $bodyContent .= '<p>' . __('Message', 'chatbot') . ' : ' . $message . '</p>';
1161 - $bodyContent .= '<p>' . __('Mail Generated on', 'chatbot') . ': ' . current_time('F j, Y, g:i a') . '</p>';
981 + $bodyContent .= '<p><strong>' . __('Support Request Details', 'wpchatbot') . ':</strong></p><hr>';
982 + $bodyContent .= '<p>' . __('Name', 'wpchatbot') . ' : ' . $name . '</p>';
983 + $bodyContent .= '<p>' . __('Email', 'wpchatbot') . ' : ' . $email . '</p>';
984 + $bodyContent .= '<p>' . __('Subject', 'wpchatbot') . ' : ' . $subject . '</p>';
985 + $bodyContent .= '<p>' . __('Message', 'wpchatbot') . ' : ' . $message . '</p>';
986 + $bodyContent .= '<p>' . __('Mail Generated on', 'wpchatbot') . ': ' . current_time('F j, Y, g:i a') . '</p>';
1162 987 $to = $toEmail;
1163 988 $body = $bodyContent;
1164 989 $headers = array();
1165 990 $headers[] = 'Content-Type: text/html; charset=UTF-8';
@@ -1171,9 +996,9 @@
1171 996 $response['message'] = str_replace('\\', '',wp_kses_post(get_option('qlcd_wp_chatbot_email_sent')));
1172 997 }
1173 998
1174 999 }
1175 - echo wp_json_encode($response);
1000 + echo json_encode($response);
1176 1001 die();
1177 1002 }
1178 1003 //Support Phone
1179 1004 add_action('wp_ajax_qcld_wb_chatbot_support_phone', 'qcld_wb_chatbot_support_phone');
@@ -1178,15 +1003,14 @@
1178 1003 //Support Phone
1179 1004 add_action('wp_ajax_qcld_wb_chatbot_support_phone', 'qcld_wb_chatbot_support_phone');
1180 1005 add_action('wp_ajax_nopriv_qcld_wb_chatbot_support_phone', 'qcld_wb_chatbot_support_phone');
1181 1006 function qcld_wb_chatbot_support_phone(){
1182 - check_ajax_referer('qcsecretbotnonceval123qc', 'nonce');
1183 - $name = trim(sanitize_text_field(wp_unslash($_POST['name'])));
1184 - $phone =sanitize_text_field(wp_unslash($_POST['phone']));
1007 + $name = trim(sanitize_text_field($_POST['name']));
1008 + $phone =sanitize_text_field($_POST['phone']);
1185 1009 $subject = 'WPBot Support Mail Request for Call Back';
1186 1010 //Extract Domain
1187 1011 $url = get_site_url();
1188 - $url = wp_parse_url($url);
1012 + $url = parse_url($url);
1189 1013 $domain = $url['host'];
1190 1014 //$admin_email = "admin@" . $domain;
1191 1015 $admin_email = get_option('admin_email');
1192 1016 $toEmail = sanitize_email(get_option('qlcd_wp_chatbot_admin_email') != '' ? get_option('qlcd_wp_chatbot_admin_email') : $admin_email);
@@ -1201,14 +1025,14 @@
1201 1025 $response['status'] = 'fail';
1202 1026 $response['message'] = str_replace('\\', '',wp_kses_post(get_option('qlcd_wp_chatbot_phone_fail')));
1203 1027 //build email body
1204 1028 $bodyContent = "";
1205 - $bodyContent .= '<p><strong>' . __('Support Request Details', 'chatbot') . ':</strong></p><hr>';
1206 - $bodyContent .= '<p>' . __('Name', 'chatbot') . ' : ' . $name . '</p>';
1207 - $bodyContent .= '<p>' . __('Phone', 'chatbot') . ' : ' . $phone . '</p>';
1208 - $bodyContent .= '<p>' . __('Subject', 'chatbot') . ' : ' . $subject . '</p>';
1209 - $bodyContent .= '<p>' . __('Message', 'chatbot') . ' : ' . __(' Call me at ', 'chatbot'). $phone . '</p>';
1210 - $bodyContent .= '<p>' . __('Mail Generated on', 'chatbot') . ': ' . current_time('F j, Y, g:i a') . '</p>';
1029 + $bodyContent .= '<p><strong>' . __('Support Request Details', 'wpchatbot') . ':</strong></p><hr>';
1030 + $bodyContent .= '<p>' . __('Name', 'wpchatbot') . ' : ' . $name . '</p>';
1031 + $bodyContent .= '<p>' . __('Phone', 'wpchatbot') . ' : ' . $phone . '</p>';
1032 + $bodyContent .= '<p>' . __('Subject', 'wpchatbot') . ' : ' . $subject . '</p>';
1033 + $bodyContent .= '<p>' . __('Message', 'wpchatbot') . ' : ' . __(' Call me at ', 'wpchatbot'). $phone . '</p>';
1034 + $bodyContent .= '<p>' . __('Mail Generated on', 'wpchatbot') . ': ' . current_time('F j, Y, g:i a') . '</p>';
1211 1035 $to = $toEmail;
1212 1036 $body = $bodyContent;
1213 1037 $headers = array();
1214 1038 $headers[] = 'Content-Type: text/html; charset=UTF-8';
@@ -1218,15 +1042,15 @@
1218 1042 if ($result) {
1219 1043 $response['status'] = 'success';
1220 1044 $response['message'] = str_replace('\\', '',wp_kses_post(get_option('qlcd_wp_chatbot_phone_sent')));
1221 1045 }
1222 - echo wp_json_encode($response);
1046 + echo json_encode($response);
1223 1047 die();
1224 1048 }
1225 1049 // Order Status part. removed
1226 1050
1227 1051 function wpb_randmom_message_handle($items){
1228 - return $items[wp_rand(0, count($items) - 1)];
1052 + return $items[rand(0, count($items) - 1)];
1229 1053 }
1230 1054 function qcld_wb_chatbot_func_str_replace($messages = array()){
1231 1055 $refined_mesgses = array();
1232 1056 foreach ($messages as $message) {
@@ -1241,10 +1065,10 @@
1241 1065 // First check the nonce, if it fails the function will break
1242 1066 check_ajax_referer('wpwbot-order-nonce', 'security');
1243 1067 // Nonce is checked, get the POST data and sign user on
1244 1068 $info = array();
1245 - $info['user_login'] = trim(sanitize_text_field(wp_unslash($_POST['user_name'])));
1246 - $info['user_password'] = trim(sanitize_text_field(wp_unslash($_POST['user_pass'])));
1069 + $info['user_login'] = trim(sanitize_text_field($_POST['user_name']));
1070 + $info['user_password'] = trim(sanitize_text_field($_POST['user_pass']));
1247 1071 $info['remember'] = true;
1248 1072 $user_signon = wp_signon($info, false);
1249 1073 $response = array();
1250 1074 if (is_wp_error($user_signon)) {
@@ -1284,12 +1108,12 @@
1284 1108 if ($response['order_num'] > 0) {
1285 1109 $response['message'] .= wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_order_found'))));
1286 1110 $order_html .= '<div class="wp-chatbot-orders-container">
1287 1111 <div class="wp-chatbot-orders-header">
1288 - <div class="order-id">' . __('ID', 'chatbot') . '</div>
1289 - <div class="order-date">' . __('Date', 'chatbot') . ' </div>
1290 - <div class="order-items">' . __('Items', 'chatbot') . '</div>
1291 - <div class="order-status">' . __('Status', 'chatbot') . '</div>
1112 + <div class="order-id">' . __('ID', 'wpchatbot') . '</div>
1113 + <div class="order-date">' . __('Date', 'wpchatbot') . ' </div>
1114 + <div class="order-items">' . __('Items', 'wpchatbot') . '</div>
1115 + <div class="order-status">' . __('Status', 'wpchatbot') . '</div>
1292 1116 </div>';
1293 1117 foreach ($customer_orders as $order) {
1294 1118 //Formatting order summery
1295 1119 if (isset($_COOKIE['from_app']) && $_COOKIE['from_app'] == 'yes') {
@@ -1300,9 +1124,9 @@
1300 1124 $order_url = '<a href="' . get_url(get_permalink(get_option('wpcommerce_myaccount_page_id')) . '/view-order/' . $order->ID) . '" target="_blank" >' . $order->ID . '</a>';
1301 1125 }
1302 1126 $order_html .= '<div class="wp-chatbot-orders-single">
1303 1127 <div class="order-id"> ' . $order_url . '</div>
1304 - <div class="order-date"> <p>' . gmdate("m/d/Y", strtotime($order->post_date)) . '</p> </div>
1128 + <div class="order-date"> <p>' . date("m/d/Y", strtotime($order->post_date)) . '</p> </div>
1305 1129 <div class="order-items">';
1306 1130 $singleOrder = new WC_Order($order->ID);
1307 1131 $items = $singleOrder->get_items();
1308 1132 foreach ($items as $item) {
@@ -1402,9 +1226,9 @@
1402 1226 $html .= get_the_post_thumbnail(get_the_ID(), 'shop_catalog') . '
1403 1227 <div class="wp-chatbot-product-summary">
1404 1228 <div class="wp-chatbot-product-table">
1405 1229 <div class="wp-chatbot-product-table-cell">
1406 - <h3 class="wp-chatbot-product-title">' . esc_html($product->post->post_title) . '</h3>
1230 + <h3 class="wp-chatbot-product-title">' . $product->post->post_title . '</h3>
1407 1231 <div class="price">' . $product->get_price_html() . '</div>';
1408 1232 $html .= ' </div>
1409 1233 </div>
1410 1234 </div></a>
@@ -1473,9 +1297,9 @@
1473 1297 $html .= get_the_post_thumbnail(get_the_ID(), 'shop_catalog') . '
1474 1298 <div class="wp-chatbot-product-summary">
1475 1299 <div class="wp-chatbot-product-table">
1476 1300 <div class="wp-chatbot-product-table-cell">
1477 - <h3 class="wp-chatbot-product-title">' . esc_html($product->post->post_title) . '</h3>
1301 + <h3 class="wp-chatbot-product-title">' . $product->post->post_title . '</h3>
1478 1302 <div class="price">' . $product->get_price_html() . '</div>';
1479 1303 $html .= ' </div>
1480 1304 </div>
1481 1305 </div></a>
@@ -1485,9 +1309,9 @@
1485 1309 wp_reset_postdata();
1486 1310 $html .= '</ul></div>';
1487 1311 } else {
1488 1312 $html .= '<div class="wp-chatbot-products-area">';
1489 - $html .= '<p style="text-align: center">' . __('You have no products', 'chatbot') . ' !';
1313 + $html .= '<p style="text-align: center">' . __('You have no products', 'wpchatbot') . ' !';
1490 1314 $html .= '</div>';
1491 1315 }
1492 1316 return $html;
1493 1317 }
@@ -1649,12 +1473,11 @@
1649 1473 //Updating the cart items.
1650 1474 add_action('wp_ajax_qcld_wb_chatbot_update_cart_item_number', 'qcld_wb_chatbot_update_cart_item_number');
1651 1475 add_action('wp_ajax_nopriv_qcld_wb_chatbot_update_cart_item_number', 'qcld_wb_chatbot_update_cart_item_number');
1652 1476 function qcld_wb_chatbot_update_cart_item_number(){
1653 - check_ajax_referer( 'wp_chatbot', 'nonce' );
1654 1477 //getting cart items n
1655 - $cart_item_key = sanitize_text_field(wp_unslash($_POST['cart_item_key']));
1656 - $qnty = sanitize_text_field(wp_unslash($_POST['qnty']));
1478 + $cart_item_key = sanitize_text_field($_POST['cart_item_key']);
1479 + $qnty = sanitize_text_field($_POST['qnty']);
1657 1480 global $wpcommerce;
1658 1481 $result = $wpcommerce->cart->set_quantity($cart_item_key, $qnty);
1659 1482 wp_send_json($result);
1660 1483 }
@@ -1661,11 +1484,10 @@
1661 1484 //Show item after removing from cart page.
1662 1485 add_action('wp_ajax_qcld_wb_chatbot_cart_item_remove', 'qcld_wb_chatbot_cart_item_remove');
1663 1486 add_action('wp_ajax_nopriv_qcld_wb_chatbot_cart_item_remove', 'qcld_wb_chatbot_cart_item_remove');
1664 1487 function qcld_wb_chatbot_cart_item_remove(){
1665 - check_ajax_referer( 'wp_chatbot', 'nonce' );
1666 1488 //getting cart items n
1667 - $cart_item_key = sanitize_text_field(wp_unslash($_POST['cart_item']));
1489 + $cart_item_key = sanitize_text_field($_POST['cart_item']);
1668 1490 global $wpcommerce;
1669 1491 $result = $wpcommerce->cart->remove_cart_item($cart_item_key);
1670 1492 wp_send_json($result);
1671 1493 }
@@ -1702,9 +1524,9 @@
1702 1524 $response = array('status' => $status, 'html' => $html);
1703 1525 wp_send_json($response);
1704 1526 }
1705 1527 //_dynamic_intent
1706 -function qcld_dynamic_intent(){
1528 +function qc_dynamic_intent(){
1707 1529 global $wpdb;
1708 1530 $intents = array();
1709 1531
1710 1532 $ai_df = get_option('enable_wp_chatbot_dailogflow');
@@ -1721,9 +1543,9 @@
1721 1543
1722 1544 if(class_exists('Qcformbuilder_Forms_Admin')){
1723 1545
1724 1546
1725 - $results = $wpdb->get_results($wpdb->prepare("SELECT * FROM ". $wpdb->prefix."wfb_forms WHERE type= %s",'primary')); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1547 + $results = $wpdb->get_results($wpdb->prepare("SELECT * FROM ". $wpdb->prefix."wfb_forms WHERE type= %s",'primary')); //DB Call OK, No Caching OK
1726 1548
1727 1549 if(!empty($results)){
1728 1550
1729 1551 foreach($results as $result){
@@ -1748,10 +1570,10 @@
1748 1570 // function qcld_wb_chatbot_checkout_user_login(){
1749 1571 // // Nonce is checked, get the POST data and sign user on
1750 1572 // $info = array();
1751 1573 // //$info['nonce'] = $_POST['nonce_val'];
1752 -// $info['user_login'] = trim(sanitize_text_field(wp_unslash($_POST['user_name'])));
1753 -// $info['user_password'] = trim(sanitize_text_field(wp_unslash($_POST['user_pass'])));
1574 +// $info['user_login'] = trim(sanitize_text_field($_POST['user_name']));
1575 +// $info['user_password'] = trim(sanitize_text_field($_POST['user_pass']));
1754 1576 // $info['remember'] = true;
1755 1577 // $user_signon = wp_signon($info, false);
1756 1578 // // $response=$info;
1757 1579 // $response = array();
@@ -1792,16 +1614,15 @@
1792 1614 add_action('init', 'wp_chatbot_create_app_checkout_thankyou_page');
1793 1615 function wp_chatbot_create_app_checkout_thankyou_page(){
1794 1616 if (get_option('wp_chatbot_app_pages') == 1) {
1795 1617 //Mobile App page create
1796 - $existing_app = new WP_Query( array( 'post_type' => 'page', 'name' => 'wpwbot-mobile-app', 'post_status' => 'publish', 'posts_per_page' => 1 ) );
1797 - if ( ! $existing_app->have_posts() ) {
1618 + if (get_page_by_title('wpwBot Mobile App') == NULL) {
1798 1619 //post status and options
1799 1620 $app_page = array(
1800 1621 'comment_status' => 'closed',
1801 1622 'ping_status' => 'closed',
1802 1623 'post_author' => get_current_user_id(),
1803 - 'post_date' => gmdate('Y-m-d H:i:s'),
1624 + 'post_date' => date('Y-m-d H:i:s'),
1804 1625 'post_status' => 'publish',
1805 1626 'post_title' => 'wpwBot Mobile App',
1806 1627 'post_name' => 'wpwbot-mobile-app',
1807 1628 'post_type' => 'page',
@@ -1811,16 +1632,15 @@
1811 1632 //save the id in the database
1812 1633 update_option('wp_chatbot_app_checkout', $wpwbot_app);
1813 1634 }
1814 1635 //App checkout page create
1815 - $existing_checkout = new WP_Query( array( 'post_type' => 'page', 'name' => 'wpwbot-app-checkout', 'post_status' => 'publish', 'posts_per_page' => 1 ) );
1816 - if ( ! $existing_checkout->have_posts() ) {
1636 + if (get_page_by_title('wpwBot App Checkout') == NULL) {
1817 1637 //post status and options
1818 1638 $checkout_page = array(
1819 1639 'comment_status' => 'closed',
1820 1640 'ping_status' => 'closed',
1821 1641 'post_author' => get_current_user_id(),
1822 - 'post_date' => gmdate('Y-m-d H:i:s'),
1642 + 'post_date' => date('Y-m-d H:i:s'),
1823 1643 'post_status' => 'publish',
1824 1644 'post_title' => 'wpwBot App Checkout',
1825 1645 'post_name' => 'wpwbot-app-checkout',
1826 1646 'post_type' => 'page',
@@ -1830,16 +1650,15 @@
1830 1650 //save the id in the database
1831 1651 update_option('wp_chatbot_app_checkout', $app_checkout);
1832 1652 }
1833 1653 //App Order thank you page create
1834 - $existing_thankyou = new WP_Query( array( 'post_type' => 'page', 'name' => 'wpwbot-app-order-thankyou', 'post_status' => 'publish', 'posts_per_page' => 1 ) );
1835 - if ( ! $existing_thankyou->have_posts() ) {
1654 + if (get_page_by_title('wpwBot App Order Thank You') == NULL) {
1836 1655 //post status and options
1837 1656 $thankyou_page = array(
1838 1657 'comment_status' => 'closed',
1839 1658 'ping_status' => 'closed',
1840 1659 'post_author' => get_current_user_id(),
1841 - 'post_date' => gmdate('Y-m-d H:i:s'),
1660 + 'post_date' => date('Y-m-d H:i:s'),
1842 1661 'post_status' => 'publish',
1843 1662 'post_title' => 'wpwBot App Order Thank You',
1844 1663 'post_name' => 'wpwbot-app-order-thankyou',
1845 1664 'post_type' => 'page',
@@ -1850,9 +1669,9 @@
1850 1669 update_option('wp_chatbot_app_order_thankyou', $app_order_thankyou);
1851 1670 }
1852 1671 }
1853 1672 //Keep tracking from App by cookies
1854 - if ( isset( $_GET['from'] ) && sanitize_text_field( wp_unslash( $_GET['from'] ) ) === 'app' ) { // phpcs:ignore WordPress.Security.NonceVerification
1673 + if (isset($_GET['from']) && $_GET['from'] == 'app') {
1855 1674 if (!isset($_COOKIE['from_app'])) {
1856 1675 setcookie('from_app', 'yes', (time() + 3600), '/');
1857 1676 }
1858 1677 }
@@ -1866,9 +1685,9 @@
1866 1685 global $wp;
1867 1686 if (is_checkout() && !empty($wp->query_vars['order-received'])) {
1868 1687 $thanks_page_id = get_option('wp_chatbot_app_order_thankyou');
1869 1688 $thanks_parmanlink = esc_url(get_permalink($thanks_page_id));
1870 - wp_safe_redirect($thanks_parmanlink . '?order_id=' . $order_get_id);
1689 + wp_redirect($thanks_parmanlink . '?order_id=' . $order_get_id);
1871 1690 exit;
1872 1691 }
1873 1692 } else {
1874 1693 remove_action('wpcommerce_thankyou', 'qcld_wb_chatbot__redirect_after_purchase');
@@ -1876,12 +1695,9 @@
1876 1695 }
1877 1696 }
1878 1697
1879 1698 function qcld_choose_random($array){
1880 - if (is_array($array) && !empty($array)) {
1881 - return $array[array_rand($array)];
1882 - }
1883 - return $array;
1699 + return $array[array_rand($array)];
1884 1700 }
1885 1701
1886 1702 //User session count
1887 1703 add_action('wp_ajax_qcld_wb_chatbot_session_count', 'qcld_wb_chatbot_session_count');
@@ -1887,9 +1703,8 @@
1887 1703 add_action('wp_ajax_qcld_wb_chatbot_session_count', 'qcld_wb_chatbot_session_count');
1888 1704 add_action('wp_ajax_nopriv_qcld_wb_chatbot_session_count', 'qcld_wb_chatbot_session_count');
1889 1705 function qcld_wb_chatbot_session_count(){
1890 1706 // Nonce is checked, get the POST data and sign user on
1891 - check_ajax_referer( 'wp_chatbot', 'nonce' );
1892 1707 global $wpdb;
1893 1708 $wpdb->show_errors = true;
1894 1709 $tableuser = $wpdb->prefix.'wpbot_sessions';
1895 1710 $response = array();
@@ -1894,22 +1709,22 @@
1894 1709 $tableuser = $wpdb->prefix.'wpbot_sessions';
1895 1710 $response = array();
1896 1711
1897 1712
1898 - $session_exists = $wpdb->get_row($wpdb->prepare("select * from {$tableuser} where 1 and id = %d",1)); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, PluginCheck.Security.DirectDB.UnescapedDBParameter
1713 + $session_exists = $wpdb->get_row($wpdb->prepare("select * from $tableuser where 1 and id = %d",1)); //DB Call OK, No Caching OK
1899 1714
1900 1715 if(empty($session_exists)){
1901 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
1716 + $wpdb->insert(
1902 1717 $tableuser,
1903 1718 array(
1904 1719 'session' => 1,
1905 1720 )
1906 - );
1721 + ); //DB Call OK, No Caching OK
1907 1722 }else{
1908 1723
1909 1724 $session_id = $session_exists->id;
1910 1725
1911 - $wpdb->update( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1726 + $wpdb->update(
1912 1727 $tableuser,
1913 1728 array(
1914 1729 'session'=>($session_exists->session+1),
1915 1730 ),
@@ -1917,9 +1732,9 @@
1917 1732 array(
1918 1733 '%d',
1919 1734 ),
1920 1735 array('%d')
1921 - );
1736 + ); //DB Call OK, No Caching OK
1922 1737
1923 1738 }
1924 1739
1925 1740 wp_send_json($response);
@@ -1927,9 +1742,9 @@
1927 1742
1928 1743 /* WPBot Chat History Addon check */
1929 1744 function qcld_wpbot_is_active_chat_history(){
1930 1745
1931 - if(function_exists('qcwp_chat_session_menu_fnc') || function_exists('qcwp_chat_session_menu_fnc_free') || function_exists( 'qcpdcs_chat_session_menu_fnc' ) ){
1746 + if(function_exists('qcwp_chat_session_menu_fnc') || function_exists( 'qcpdcs_chat_session_menu_fnc' ) ){
1932 1747 return 1;
1933 1748 }else{
1934 1749 return 0;
1935 1750 }
@@ -1935,73 +1750,18 @@
1935 1750 }
1936 1751
1937 1752 }
1938 1753
1939 -/**
1940 - * Safely sanitize chatbot conversation input.
1941 - *
1942 - * SECURITY FIX (CVE WPBot Stored XSS ≤ 8.6.9):
1943 - * The previous order was: wp_kses() → html_entity_decode() → htmlspecialchars().
1944 - * An attacker could submit entity-encoded payloads (&lt;img onerror=...&gt;) that
1945 - * bypassed wp_kses (which saw inert text), were then decoded back into live markup
1946 - * by html_entity_decode(), and survived into storage and the admin UI.
1947 - *
1948 - * Correct order: html_entity_decode() FIRST → wp_kses() → htmlspecialchars().
1949 - * wp_kses() now sees the real decoded markup and strips forbidden tags/attributes.
1950 - *
1951 - * @param string $data Raw conversation string (already wp_unslash'd by caller).
1952 - * @return string Sanitized, entity-encoded string safe for DB storage.
1953 - */
1954 -function qcld_wpbot_input_validation( $data ) {
1955 - // 1. Decode any entity-encoded HTML so wp_kses sees the real markup.
1956 - $data = html_entity_decode( $data, ENT_QUOTES | ENT_HTML5, 'UTF-8' );
1957 - $data = trim( $data );
1958 - $data = stripslashes( $data );
1959 - // 2. Sanitize with a strict allowlist — NOW operating on decoded markup.
1960 - $data = wp_kses( $data, wpbot_get_safe_conversation_tags() );
1961 - // 3. Re-encode for safe DB storage; admin.js decodes for rendering.
1962 - $data = htmlspecialchars( $data, ENT_QUOTES | ENT_HTML5, 'UTF-8' );
1754 +function qc_wpbot_input_validation( $data ) {
1755 + $data = html_entity_decode($data);
1756 + $data = trim($data);
1757 + $data = stripslashes($data);
1758 + $data = htmlspecialchars($data);
1963 1759 return $data;
1964 1760 }
1761 +add_action('wp_ajax_small_talk_import', 'small_talk_import');
1762 +function small_talk_import(){
1965 1763
1966 -/**
1967 - * Returns the strict HTML allowlist for chatbot conversation content.
1968 - *
1969 - * Critically: no event-handler attributes (onerror, onclick, onload, etc.) are
1970 - * allowed — wp_kses strips any attribute not explicitly listed here.
1971 - * 'img' is intentionally omitted; bot responses that include images should use
1972 - * safe URLs only and can be re-added with only 'src', 'alt', 'class' if needed.
1973 - *
1974 - * @return array<string, array<string, bool>>
1975 - */
1976 -function wpbot_get_safe_conversation_tags() {
1977 - return array(
1978 - 'ul' => array( 'class' => true ),
1979 - 'ol' => array( 'class' => true ),
1980 - 'li' => array( 'class' => true, 'id' => true ),
1981 - 'div' => array( 'class' => true, 'id' => true ),
1982 - 'span' => array( 'class' => true, 'id' => true ),
1983 - 'p' => array( 'class' => true ),
1984 - 'br' => array(),
1985 - 'strong' => array(),
1986 - 'em' => array(),
1987 - 'b' => array(),
1988 - 'i' => array(),
1989 - 'a' => array(
1990 - 'href' => true,
1991 - 'target' => true,
1992 - 'rel' => true,
1993 - 'class' => true,
1994 - ),
1995 - // 'img' intentionally excluded — prevents onerror/onload injection.
1996 - // Add back with only 'src','alt','class' if bot image responses are needed.
1997 - );
1998 -}
1999 -add_action('wp_ajax_qcld_small_talk_import', 'qcld_small_talk_import');
2000 -function qcld_small_talk_import(){
2001 - if ( ! current_user_can( 'manage_options' ) ) {
2002 - wp_die();
2003 - }
2004 1764 global $wpdb;
2005 1765
2006 1766 $table = $wpdb->prefix.'wpbot_response';
2007 1767
@@ -2008,10 +1768,9 @@
2008 1768 $csvFile = file(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . 'small_talk.csv');
2009 1769
2010 1770 foreach ($csvFile as $line) {
2011 1771 $line = str_getcsv($line, ',', '"');
2012 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
2013 - $table, array(
1772 + $wpdb->insert($table, array(
2014 1773 'query' => $line[0],
2015 1774 'keyword' => $line[1],
2016 1775 'response' => $line[2],
2017 1776 'category'=> $line[3],
@@ -2016,17 +1775,16 @@
2016 1775 'response' => $line[2],
2017 1776 'category'=> $line[3],
2018 1777 'intent'=> '',
2019 1778 //'lang'=> 'en_US',
2020 - ));
1779 + )); //DB Call OK, No Caching OK
2021 1780 }
2022 1781
2023 1782 $table2 = $wpdb->prefix.'wpbot_response_category';
2024 1783
2025 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
2026 - $table2, array(
1784 + $wpdb->insert($table2, array(
2027 1785 'name' => 'smalltalk',
2028 - ));
1786 + )); //DB Call OK, No Caching OK
2029 1787
2030 1788 update_option( 'qcld_small_talk_imported', 'yes' );
2031 1789
2032 1790 }
@@ -2045,36 +1803,5 @@
2045 1803 }
2046 1804 function qcld_wpbot_meta_tags() {
2047 1805 echo '<!-- "This site uses ChatBot for WordPress - WPBot from https://www.wpbot.pro/" -->';
2048 1806 }
2049 -add_action('wp_footer', 'qcld_wpbot_meta_tags', 100);
2050 -
2051 -if ( ! function_exists( 'qcld_change_language_from_center' ) ) {
2052 - add_action( 'wp_ajax_qcld_change_language_from_center', 'qcld_change_language_from_center' );
2053 - add_action( 'wp_ajax_nopriv_qcld_change_language_from_center', 'qcld_change_language_from_center' );
2054 - function qcld_change_language_from_center() {
2055 - if ( ! current_user_can( 'manage_options' ) ) {
2056 - wp_send_json_error( array( 'message' => 'Unauthorized.' ) );
2057 - }
2058 - $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( wp_unslash( $_POST['nonce'] ) ) : '';
2059 - if ( ! wp_verify_nonce( $nonce, 'wp_chatbot' ) ) {
2060 - wp_send_json_error( array( 'message' => 'Invalid nonce.' ) );
2061 - }
2062 - $plugin_path = plugin_dir_path( __FILE__ );
2063 - include $plugin_path . 'includes/admin/settings-fields.php';
2064 - $json_file_path = $plugin_path . 'includes/language-center.json';
2065 -
2066 - $json_string = file_get_contents( $json_file_path );
2067 - if ( isset( $_POST['language'] ) ) {
2068 - $language = sanitize_text_field( wp_unslash( $_POST['language'] ) );
2069 - $language_array= json_decode($json_string)->$language;
2070 - update_option( 'wp_chatbot_language_center_language', $language );
2071 - wp_send_json_success( array( 'message' => true, 'data' => $language_array, 'language' => $language ) );
2072 - } else {
2073 - wp_send_json_error( array( 'message' => 'Language not specified.' ) );
2074 -
2075 - }
2076 - }
2077 -}
2078 -
2079 -// AI Actions Chat Preview
2080 -
1807 +add_action('wp_footer', 'qcld_wpbot_meta_tags', 100);