PluginProbe
WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services / 7.6.0
WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services v7.6.0
8.7.8 8.7.7 8.7.6 8.7.5 8.7.4 8.7.3 8.7.2 8.7.1 8.7.0 8.6.9 8.6.8 8.6.7 8.6.6 8.6.5 8.6.4 8.6.2 8.6.1 8.6.0 8.5.9 8.5.8 8.5.7 8.5.6 8.5.5 8.5.4 8.5.3 All 534 releases
← All changes | functions.php +70 -135 8.6.57.6.0 View file →
@@ -3,46 +3,9 @@
3 3 * @param $type
4 4 * Display wpwBot Icon ball
5 5 */
6 6 if (!defined('ABSPATH')) exit; // Exit if accessed directly
7 -
8 -
9 -function qcld_custom_search_form( $form ) {
10 - // Add a hidden input to limit search to 'product' post type
11 - if (get_option('wp_chatbot_agent_image') == "custom-agent.png") {
12 - $wp_chatbot_custom_agent_path = get_option('wp_chatbot_custom_agent_path');
13 - } else if (get_option('wp_chatbot_agent_image') != "custom-agent.png") {
14 - $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_agent_image');
15 - } else {
16 - $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . 'custom-agent.png';
17 - }
18 - $hidden_field = '<a class="wp-chatbot qc_wpbot_chat_link" id="wp-chatbot-search-btn" data-search-type="product" data-search-term="" style="max-height: 50px; margin-left: 10px;padding: 0 !important;position: absolute;top: -9px;right: -60px;"><img src="'. esc_url($wp_chatbot_custom_agent_path) .'" alt=""></a>';
19 - $block_content = str_replace( '</form>', $hidden_field . '</form>', $form );
20 - return $block_content;
21 -}
22 -if(get_option('wpbot_enable_on_search') == 1 && (get_option('disable_floating_button') != '1') && get_option('disable_wp_chatbot') != 1 ){
23 - add_filter( 'get_search_form', 'qcld_custom_search_form' );
24 - add_filter( 'render_block_core/search', 'qcld_modify_gutenberg_search_block', 10, 2 );
25 -}
26 -
27 -
28 -function qcld_modify_gutenberg_search_block( $block_content, $block ) {
29 - // Add a hidden input to limit search to 'product' post type
30 - if (get_option('wp_chatbot_agent_image') == "custom-agent.png") {
31 - $wp_chatbot_custom_agent_path = get_option('wp_chatbot_custom_agent_path');
32 - } else if (get_option('wp_chatbot_agent_image') != "custom-agent.png") {
33 - $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_agent_image');
34 - } else {
35 - $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . 'custom-agent.png';
36 - }
37 - $hidden_field = '<button type="button" class="wp-chatbot qc_wpbot_chat_link" id="wp-chatbot-search-btn" data-search-type="product" data-search-term="" style="max-height: 50px; margin-left: 10px;padding: 0 !important"><img src="'. esc_url($wp_chatbot_custom_agent_path) .'" alt=""></button>';
38 - // Inject the hidden field before the closing </form> tag
39 - $block_content = str_replace( '</div></form>', $hidden_field . '</div></form>', $block_content );
40 - return $block_content;
41 -}
42 -if(get_option('disable_floating_button') != '1'){
43 - add_action('wp_footer', 'wp_chatbot_load_footer_html');
44 -}
7 +add_action('wp_footer', 'wp_chatbot_load_footer_html');
45 8 add_action( 'admin_footer', 'qcld_style_for_hide_iframe');
46 9 function qcld_style_for_hide_iframe(){
47 10 ?>
48 11 <script>
@@ -65,9 +28,9 @@
65 28 ?>
66 29 <style>
67 30 <?php if(get_option('wp_chatbot_custom_css')!="") {
68 31
69 - echo wp_strip_all_tags( get_option('wp_chatbot_custom_css') );// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
32 + echo get_option('wp_chatbot_custom_css');
70 33 }
71 34 ?>
72 35 </style>
73 36
@@ -92,9 +55,9 @@
92 55 // if (get_option('enable_wp_chatbot_mobile_full_screen')==1) {
93 56 $wp_chatbot_enable_mobile_screen .= "wp-chatbot-mobile-full-screen";
94 57 // }
95 58 ?>
96 - <div id="wp-chatbot-chat-container" class="<?php echo esc_attr($wp_chatbot_enable_rtl .' '.$wp_chatbot_enable_mobile_screen); ?>" style="<?php if(get_option('disable_floating_button') == '1'){ echo 'display:none';} ?>">
59 + <div id="wp-chatbot-chat-container" class="<?php echo esc_attr($wp_chatbot_enable_rtl .' '.$wp_chatbot_enable_mobile_screen); ?>">
97 60 <div id="wp-chatbot-integration-container">
98 61 <div class="wp-chatbot-integration-button-container">
99 62 <?php if (get_option('enable_wp_chatbot_skype_floating_icon') == 1) { ?>
100 63 <a href="skype:<?php echo esc_attr(get_option('enable_wp_chatbot_skype_id')); ?>?chat"><span
@@ -155,9 +118,9 @@
155 118 }
156 119 ?>
157 120 <div class="wp-chatbot-notification-agent-profile">
158 121 <div class="wp-chatbot-notification-widget-avatar" ><img
159 - src="<?php echo esc_url($wp_chatbot_custom_agent_path); ?>" alt=""></div>
122 + src="<?php echo esc_attr($wp_chatbot_custom_agent_path); ?>" alt=""></div>
160 123 <div class="wp-chatbot-notification-welcome"><?php echo wp_kses_post(wpb_randmom_message_handle(maybe_unserialize(get_option('qlcd_wp_chatbot_welcome')))) . ' <strong>' . esc_html(get_option('qlcd_wp_chatbot_host')) . '</strong>'; ?></div>
161 124 </div>
162 125 <?php
163 126 //update_option('qlcd_wp_chatbot_notifications','Welcome to WpBot');
@@ -313,10 +276,10 @@
313 276 }
314 277 }
315 278 //Checking wpwbot opening hour
316 279 function wp_chatbot_check_opening_hours(){
317 - $curent_day=strtolower(gmdate('l',strtotime(current_time( 'mysql' ))));
318 - $current_time=gmdate('H:i',strtotime(current_time( 'mysql')));
280 + $curent_day=strtolower(date('l',strtotime(current_time( 'mysql' ))));
281 + $current_time=date('H:i',strtotime(current_time( 'mysql')));
319 282 $is_wpwbot_open =false;
320 283 if(get_option('wpwbot_hours')) {
321 284 $wpwbot_times = wp_kses_post(unserialize(get_option('wpwbot_hours')));
322 285 if (isset($wpwbot_times[$curent_day])) {
@@ -338,16 +301,9 @@
338 301 */
339 302 add_action('wp_ajax_qcld_wb_chatbot_keyword', 'qcld_wb_chatbot_keyword');
340 303 add_action('wp_ajax_nopriv_qcld_wb_chatbot_keyword', 'qcld_wb_chatbot_keyword');
341 304 function qcld_wb_chatbot_keyword(){
342 - // Verify nonce for security
343 - $nonce = isset($_POST['security']) ? sanitize_text_field(wp_unslash($_POST['security'])) : (isset($_POST['nonce']) ? sanitize_text_field(wp_unslash($_POST['nonce'])) : '');
344 - if ( ! wp_verify_nonce( $nonce, 'wp_chatbot' ) && ! wp_verify_nonce( $nonce, 'qcsecretbotnonceval123qc' ) ) {
345 - wp_send_json_error( array( 'status' => 'fail', 'message' => 'Security check failed.' ) );
346 - wp_die();
347 - }
348 -
349 - $keyword = sanitize_text_field(wp_unslash($_POST['keyword']));
305 + $keyword = sanitize_text_field($_POST['keyword']);
350 306 $product_per_page = get_option('qlcd_wp_chatbot_ppp') != '' ? get_option('qlcd_wp_chatbot_ppp') : 10;
351 307 if (get_option('qlcd_wp_chatbot_search_option') == 'standard') {
352 308 $product_orderby = sanitize_text_field(get_option('qlcd_wp_chatbot_product_orderby') != '' ? get_option('qlcd_wp_chatbot_product_orderby') : 'title');
353 309 $product_order = sanitize_text_field(get_option('qlcd_wp_chatbot_product_order') != '' ? get_option('qlcd_wp_chatbot_product_order') : 'ASC');
@@ -393,9 +349,9 @@
393 349 endwhile;
394 350 wp_reset_postdata();
395 351 $html .= '</ul>';
396 352 if ($total_product_num > $product_per_page && $product_per_page > 0 ) {
397 - $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . esc_attr($keyword) . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
353 + $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . $keyword . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
398 354 }
399 355 }
400 356 $html .= '</div>';
401 357 } else if (get_option('qlcd_wp_chatbot_search_option') == 'advanced') {
@@ -423,9 +379,9 @@
423 379 }
424 380 }
425 381 $html .= '</ul>';
426 382 if ($total_product_num > $product_per_page && $product_per_page > 0) {
427 - $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . esc_attr($more_product_ids) . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
383 + $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . $more_product_ids . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
428 384 }
429 385 }
430 386 $html .= '</div>';
431 387 }
@@ -440,15 +396,16 @@
440 396 add_action('wp_ajax_nopriv_qcld_wb_chatbot_category', 'qcld_wb_chatbot_category');
441 397 function qcld_wb_chatbot_category(){
442 398 $category_type="common";
443 399 if (get_option('wp_chatbot_show_parent_category') != "") {
444 - $terms = get_terms( array( 'taxonomy' => 'product_cat', 'parent' => 0, 'hide_empty' => true, 'fields' => 'all' ) );
400 + $terms = get_terms('product_cat', array('parent' => 0, 'hide_empty' => true, 'fields' => 'all'));
401 +
445 402 } else {
446 - $terms = get_terms( array( 'taxonomy' => 'product_cat', 'hide_empty' => true, 'fields' => 'all' ) );
403 + $terms = get_terms('product_cat', array('hide_empty' => true, 'fields' => 'all'));
447 404 }
448 405 $html = "";
449 406 foreach ($terms as $term) {
450 - $child_terms=get_terms( array( 'taxonomy' => 'product_cat', 'parent' => $term->term_id, 'hide_empty' => true, 'fields' => 'all' ) );
407 + $child_terms=get_terms('product_cat', array('parent' => $term->term_id, 'hide_empty' => true, 'fields' => 'all'));
451 408 if(get_option('wp_chatbot_show_sub_category')==1 && count($child_terms) >0){
452 409 $category_type="hasChilds";
453 410 }
454 411 $html .= '<span class="qcld-chatbot-product-category" data-category-type="' . $category_type . '" data-category-slug="' . $term->slug . '" data-category-id="' . $term->term_id . '">' . $term->name . '</span>';
@@ -461,10 +418,10 @@
461 418 */
462 419 add_action('wp_ajax_qcld_wb_chatbot_sub_category', 'qcld_wb_chatbot_sub_category');
463 420 add_action('wp_ajax_nopriv_qcld_wb_chatbot_sub_category', 'qcld_wb_chatbot_sub_category');
464 421 function qcld_wb_chatbot_sub_category(){
465 - $parent_id = intval( wp_unslash( $_POST['parent_id'] ) );
466 - $terms = get_terms( array( 'taxonomy' => 'product_cat', 'parent' => $parent_id, 'hide_empty' => true, 'fields' => 'all' ) );
422 + $parent_id = stripslashes($_POST['parent_id']);
423 + $terms = get_terms('product_cat', array('parent' => $parent_id, 'hide_empty' => true, 'fields' => 'all'));
467 424 $html = "";
468 425 foreach ($terms as $term) {
469 426 $html .= '<span class="qcld-chatbot-product-category" data-category-type="common" data-category-slug="' . $term->slug . '" data-category-id="' . $term->term_id . '">' . $term->name . '</span>';
470 427 }
@@ -476,9 +433,9 @@
476 433 */
477 434 add_action('wp_ajax_qcld_wb_chatbot_category_products', 'qcld_wb_chatbot_category_products');
478 435 add_action('wp_ajax_nopriv_qcld_wb_chatbot_category_products', 'qcld_wb_chatbot_category_products');
479 436 function qcld_wb_chatbot_category_products(){
480 - $category_id = intval( wp_unslash( $_POST['category'] ) );
437 + $category_id = stripslashes($_POST['category']);
481 438 $product_per_page = sanitize_text_field(get_option('qlcd_wp_chatbot_ppp') != '' ? get_option('qlcd_wp_chatbot_ppp') : 10);
482 439 $product_orderby = sanitize_text_field(get_option('qlcd_wp_chatbot_product_orderby') != '' ? get_option('qlcd_wp_chatbot_product_orderby') : 'title');
483 440 $product_order = sanitize_text_field(get_option('qlcd_wp_chatbot_product_order') != '' ? get_option('qlcd_wp_chatbot_product_order') : 'ASC');
484 441 //Merging all query together.
@@ -715,11 +672,11 @@
715 672 //load more
716 673 add_action('wp_ajax_qcld_wb_chatbot_load_more', 'qcld_wb_chatbot_load_more');
717 674 add_action('wp_ajax_nopriv_qcld_wb_chatbot_load_more', 'qcld_wb_chatbot_load_more');
718 675 function qcld_wb_chatbot_load_more(){
719 - $offset = intval( wp_unslash( $_POST['offset'] ) );
720 - $search_type = sanitize_text_field( wp_unslash( $_POST['search_type'] ) );
721 - $search_term = sanitize_text_field( wp_unslash( $_POST['search_term'] ) );
676 + $offset = stripslashes($_POST['offset']);
677 + $search_type = stripslashes($_POST['search_type']);
678 + $search_term = stripslashes($_POST['search_term']);
722 679 $product_per_page = sanitize_text_field(get_option('qlcd_wp_chatbot_ppp') != '' ? get_option('qlcd_wp_chatbot_ppp') : 10);
723 680 $product_orderby = sanitize_text_field(get_option('qlcd_wp_chatbot_product_orderby') != '' ? get_option('qlcd_wp_chatbot_product_orderby') : 'title');
724 681 $product_order = sanitize_text_field(get_option('qlcd_wp_chatbot_product_order') != '' ? get_option('qlcd_wp_chatbot_product_order') : 'ASC');
725 682 $next_offset = intval($product_per_page + $offset);
@@ -850,9 +807,9 @@
850 807 //product details
851 808 add_action('wp_ajax_qcld_wb_chatbot_product_details', 'qcld_wb_chatbot_product_details');
852 809 add_action('wp_ajax_nopriv_qcld_wb_chatbot_product_details', 'qcld_wb_chatbot_product_details');
853 810 function qcld_wb_chatbot_product_details(){
854 - $product_id = intval( wp_unslash( $_POST['wp_chatbot_pid'] ) );
811 + $product_id = stripslashes($_POST['wp_chatbot_pid']);
855 812 //Tracking product view from chat board
856 813 wp_chatbot_view_track_product_by_id($product_id);
857 814 //wpcommerce product factory
858 815 $wc_pf = new WC_Product_Factory();
@@ -925,11 +882,10 @@
925 882 $variations .= '<label for="' . sanitize_title($name) . '">' . $title . '</label>';
926 883 $variations .= '<select id="' . esc_attr(sanitize_title($name)) . '" name="attribute_' . sanitize_title($name) . '" data-attribute_name="attribute_' . sanitize_title($name) . '" class="each_attribute">';
927 884 $variations .= '<option value="">' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_choose_option')))) . '</option>';
928 885 foreach ($values as $value) {
929 - $attr_key = 'attribute_' . sanitize_title( $name );
930 - if ( isset( $_REQUEST[ $attr_key ] ) ) { // phpcs:ignore WordPress.Security.NonceVerification
931 - $selected_value = sanitize_text_field( wp_unslash( $_REQUEST[ $attr_key ] ) );
886 + if (isset($_REQUEST['attribute_' . sanitize_title($name)])) {
887 + $selected_value = $_REQUEST['attribute_' . sanitize_title($name)];
932 888 } else {
933 889 $selected_value = '';
934 890 }
935 891 $variations .= '<option value="' . esc_attr(strtolower($value)) . '"' . selected($selected_value, $value, false) . '>' . apply_filters('wpcommerce_variation_option_name', $value) . '</option>';
@@ -953,12 +909,12 @@
953 909 //Add to cart for variable product.
954 910 add_action('wp_ajax_qcld_variable_add_to_cart', 'qcld_variable_add_to_cart');
955 911 add_action('wp_ajax_nopriv_qcld_variable_add_to_cart', 'qcld_variable_add_to_cart');
956 912 function qcld_variable_add_to_cart(){
957 - $product_id = intval( wp_unslash( $_POST['p_id'] ) );
958 - $quantity = intval( wp_unslash( $_POST['quantity'] ) );
959 - $variations_id = intval( wp_unslash( $_POST['variations_id'] ) );
960 - $attrs = isset( $_POST['attributes'] ) ? array_map( 'sanitize_text_field', wp_unslash( (array) $_POST['attributes'] ) ) : array();
913 + $product_id = stripslashes($_POST['p_id']);
914 + $quantity = stripslashes($_POST['quantity']);
915 + $variations_id = stripslashes($_POST['variations_id']);
916 + $attrs = stripslashes($_POST['attributes']);
961 917 //echo wp_send_json(array('p_id'=>$product_id,'qnty'=>$quantity,'id'=>$variations_id,'att'=>$attrs));
962 918 $attributes = array();
963 919 foreach ($attrs as $attr) {
964 920 $single = explode("#", $attr);
@@ -978,10 +934,10 @@
978 934 //Add to cart for simple product.
979 935 add_action('wp_ajax_qcld_wb_chatbot_add_to_cart', 'qcld_wb_chatbot_add_to_cart');
980 936 add_action('wp_ajax_nopriv_qcld_wb_chatbot_add_to_cart', 'qcld_wb_chatbot_add_to_cart');
981 937 function qcld_wb_chatbot_add_to_cart(){
982 - $product_id = intval( wp_unslash( $_POST['product_id'] ) );
983 - $product_quantity = intval( wp_unslash( $_POST['quantity'] ) );
938 + $product_id = stripslashes($_POST['product_id']);
939 + $product_quantity = stripslashes($_POST['quantity']);
984 940 global $wpcommerce;
985 941 $result = $wpcommerce->cart->add_to_cart($product_id, $product_quantity);
986 942 if ($result != false) {
987 943 wp_send_json('simple');
@@ -992,19 +948,15 @@
992 948 //Support part
993 949 add_action('wp_ajax_qcld_wb_chatbot_support_email', 'qcld_wb_chatbot_support_email');
994 950 add_action('wp_ajax_nopriv_qcld_wb_chatbot_support_email', 'qcld_wb_chatbot_support_email');
995 951 function qcld_wb_chatbot_support_email(){
996 - $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( wp_unslash( $_POST['nonce'] ) ) : '';
997 - if ( ! wp_verify_nonce( $nonce, 'qcsecretbotnonceval123qc' ) ) {
998 - wp_send_json_error( array( 'error' => esc_html__( 'Error: Invalid nonce verification.', 'chatbot' ) ) );
999 - }
1000 - $name = trim(sanitize_text_field(wp_unslash($_POST['name'])));
1001 - $email = sanitize_email(wp_unslash($_POST['email']));
1002 - $message = sanitize_text_field(wp_unslash($_POST['message']));
952 + $name = trim(sanitize_text_field($_POST['name']));
953 + $email = sanitize_email($_POST['email']);
954 + $message = sanitize_text_field($_POST['message']);
1003 955 $subject = sanitize_text_field(get_option('qlcd_wp_chatbot_email_sub') != '' ? get_option('qlcd_wp_chatbot_email_sub') : 'Support Email from wpWBot by Client');
1004 956 //Extract Domain
1005 957 $url = get_site_url();
1006 - $url = wp_parse_url($url);
958 + $url = parse_url($url);
1007 959 $domain = $url['host'];
1008 960 //$admin_email = "admin@" . $domain;
1009 961 $admin_email = sanitize_email(get_option('admin_email'));
1010 962 $toEmail = sanitize_email(get_option('qlcd_wp_chatbot_admin_email') != '' ? get_option('qlcd_wp_chatbot_admin_email') : $admin_email);
@@ -1014,8 +966,9 @@
1014 966 $fromEmail = get_option('qlcd_wp_chatbot_from_email');
1015 967 }else{
1016 968 $fromEmail = "wordpress@" . $domain;
1017 969 }
970 +
1018 971 //Starting messaging and status.
1019 972 $response['status'] = 'fail';
1020 973 $response['message'] = str_replace('\\', '',wp_kses_post(get_option('qlcd_wp_chatbot_email_fail')));
1021 974 if (filter_var($email, FILTER_VALIDATE_EMAIL) === false) {
@@ -1049,15 +1002,14 @@
1049 1002 //Support Phone
1050 1003 add_action('wp_ajax_qcld_wb_chatbot_support_phone', 'qcld_wb_chatbot_support_phone');
1051 1004 add_action('wp_ajax_nopriv_qcld_wb_chatbot_support_phone', 'qcld_wb_chatbot_support_phone');
1052 1005 function qcld_wb_chatbot_support_phone(){
1053 - check_ajax_referer('qcsecretbotnonceval123qc', 'nonce');
1054 - $name = trim(sanitize_text_field(wp_unslash($_POST['name'])));
1055 - $phone =sanitize_text_field(wp_unslash($_POST['phone']));
1006 + $name = trim(sanitize_text_field($_POST['name']));
1007 + $phone =sanitize_text_field($_POST['phone']);
1056 1008 $subject = 'WPBot Support Mail Request for Call Back';
1057 1009 //Extract Domain
1058 1010 $url = get_site_url();
1059 - $url = wp_parse_url($url);
1011 + $url = parse_url($url);
1060 1012 $domain = $url['host'];
1061 1013 //$admin_email = "admin@" . $domain;
1062 1014 $admin_email = get_option('admin_email');
1063 1015 $toEmail = sanitize_email(get_option('qlcd_wp_chatbot_admin_email') != '' ? get_option('qlcd_wp_chatbot_admin_email') : $admin_email);
@@ -1095,9 +1047,9 @@
1095 1047 }
1096 1048 // Order Status part. removed
1097 1049
1098 1050 function wpb_randmom_message_handle($items){
1099 - return $items[wp_rand(0, count($items) - 1)];
1051 + return $items[rand(0, count($items) - 1)];
1100 1052 }
1101 1053 function qcld_wb_chatbot_func_str_replace($messages = array()){
1102 1054 $refined_mesgses = array();
1103 1055 foreach ($messages as $message) {
@@ -1112,10 +1064,10 @@
1112 1064 // First check the nonce, if it fails the function will break
1113 1065 check_ajax_referer('wpwbot-order-nonce', 'security');
1114 1066 // Nonce is checked, get the POST data and sign user on
1115 1067 $info = array();
1116 - $info['user_login'] = trim(sanitize_text_field(wp_unslash($_POST['user_name'])));
1117 - $info['user_password'] = trim(sanitize_text_field(wp_unslash($_POST['user_pass'])));
1068 + $info['user_login'] = trim(sanitize_text_field($_POST['user_name']));
1069 + $info['user_password'] = trim(sanitize_text_field($_POST['user_pass']));
1118 1070 $info['remember'] = true;
1119 1071 $user_signon = wp_signon($info, false);
1120 1072 $response = array();
1121 1073 if (is_wp_error($user_signon)) {
@@ -1171,9 +1123,9 @@
1171 1123 $order_url = '<a href="' . get_url(get_permalink(get_option('wpcommerce_myaccount_page_id')) . '/view-order/' . $order->ID) . '" target="_blank" >' . $order->ID . '</a>';
1172 1124 }
1173 1125 $order_html .= '<div class="wp-chatbot-orders-single">
1174 1126 <div class="order-id"> ' . $order_url . '</div>
1175 - <div class="order-date"> <p>' . gmdate("m/d/Y", strtotime($order->post_date)) . '</p> </div>
1127 + <div class="order-date"> <p>' . date("m/d/Y", strtotime($order->post_date)) . '</p> </div>
1176 1128 <div class="order-items">';
1177 1129 $singleOrder = new WC_Order($order->ID);
1178 1130 $items = $singleOrder->get_items();
1179 1131 foreach ($items as $item) {
@@ -1273,9 +1225,9 @@
1273 1225 $html .= get_the_post_thumbnail(get_the_ID(), 'shop_catalog') . '
1274 1226 <div class="wp-chatbot-product-summary">
1275 1227 <div class="wp-chatbot-product-table">
1276 1228 <div class="wp-chatbot-product-table-cell">
1277 - <h3 class="wp-chatbot-product-title">' . esc_html($product->post->post_title) . '</h3>
1229 + <h3 class="wp-chatbot-product-title">' . $product->post->post_title . '</h3>
1278 1230 <div class="price">' . $product->get_price_html() . '</div>';
1279 1231 $html .= ' </div>
1280 1232 </div>
1281 1233 </div></a>
@@ -1344,9 +1296,9 @@
1344 1296 $html .= get_the_post_thumbnail(get_the_ID(), 'shop_catalog') . '
1345 1297 <div class="wp-chatbot-product-summary">
1346 1298 <div class="wp-chatbot-product-table">
1347 1299 <div class="wp-chatbot-product-table-cell">
1348 - <h3 class="wp-chatbot-product-title">' . esc_html($product->post->post_title) . '</h3>
1300 + <h3 class="wp-chatbot-product-title">' . $product->post->post_title . '</h3>
1349 1301 <div class="price">' . $product->get_price_html() . '</div>';
1350 1302 $html .= ' </div>
1351 1303 </div>
1352 1304 </div></a>
@@ -1520,12 +1472,11 @@
1520 1472 //Updating the cart items.
1521 1473 add_action('wp_ajax_qcld_wb_chatbot_update_cart_item_number', 'qcld_wb_chatbot_update_cart_item_number');
1522 1474 add_action('wp_ajax_nopriv_qcld_wb_chatbot_update_cart_item_number', 'qcld_wb_chatbot_update_cart_item_number');
1523 1475 function qcld_wb_chatbot_update_cart_item_number(){
1524 - check_ajax_referer( 'wp_chatbot', 'nonce' );
1525 1476 //getting cart items n
1526 - $cart_item_key = sanitize_text_field(wp_unslash($_POST['cart_item_key']));
1527 - $qnty = sanitize_text_field(wp_unslash($_POST['qnty']));
1477 + $cart_item_key = sanitize_text_field($_POST['cart_item_key']);
1478 + $qnty = sanitize_text_field($_POST['qnty']);
1528 1479 global $wpcommerce;
1529 1480 $result = $wpcommerce->cart->set_quantity($cart_item_key, $qnty);
1530 1481 wp_send_json($result);
1531 1482 }
@@ -1532,11 +1483,10 @@
1532 1483 //Show item after removing from cart page.
1533 1484 add_action('wp_ajax_qcld_wb_chatbot_cart_item_remove', 'qcld_wb_chatbot_cart_item_remove');
1534 1485 add_action('wp_ajax_nopriv_qcld_wb_chatbot_cart_item_remove', 'qcld_wb_chatbot_cart_item_remove');
1535 1486 function qcld_wb_chatbot_cart_item_remove(){
1536 - check_ajax_referer( 'wp_chatbot', 'nonce' );
1537 1487 //getting cart items n
1538 - $cart_item_key = sanitize_text_field(wp_unslash($_POST['cart_item']));
1488 + $cart_item_key = sanitize_text_field($_POST['cart_item']);
1539 1489 global $wpcommerce;
1540 1490 $result = $wpcommerce->cart->remove_cart_item($cart_item_key);
1541 1491 wp_send_json($result);
1542 1492 }
@@ -1592,9 +1542,9 @@
1592 1542
1593 1543 if(class_exists('Qcformbuilder_Forms_Admin')){
1594 1544
1595 1545
1596 - $results = $wpdb->get_results($wpdb->prepare("SELECT * FROM ". $wpdb->prefix."wfb_forms WHERE type= %s",'primary')); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1546 + $results = $wpdb->get_results($wpdb->prepare("SELECT * FROM ". $wpdb->prefix."wfb_forms WHERE type= %s",'primary')); //DB Call OK, No Caching OK
1597 1547
1598 1548 if(!empty($results)){
1599 1549
1600 1550 foreach($results as $result){
@@ -1619,10 +1569,10 @@
1619 1569 // function qcld_wb_chatbot_checkout_user_login(){
1620 1570 // // Nonce is checked, get the POST data and sign user on
1621 1571 // $info = array();
1622 1572 // //$info['nonce'] = $_POST['nonce_val'];
1623 -// $info['user_login'] = trim(sanitize_text_field(wp_unslash($_POST['user_name'])));
1624 -// $info['user_password'] = trim(sanitize_text_field(wp_unslash($_POST['user_pass'])));
1573 +// $info['user_login'] = trim(sanitize_text_field($_POST['user_name']));
1574 +// $info['user_password'] = trim(sanitize_text_field($_POST['user_pass']));
1625 1575 // $info['remember'] = true;
1626 1576 // $user_signon = wp_signon($info, false);
1627 1577 // // $response=$info;
1628 1578 // $response = array();
@@ -1663,16 +1613,15 @@
1663 1613 add_action('init', 'wp_chatbot_create_app_checkout_thankyou_page');
1664 1614 function wp_chatbot_create_app_checkout_thankyou_page(){
1665 1615 if (get_option('wp_chatbot_app_pages') == 1) {
1666 1616 //Mobile App page create
1667 - $existing_app = new WP_Query( array( 'post_type' => 'page', 'name' => 'wpwbot-mobile-app', 'post_status' => 'publish', 'posts_per_page' => 1 ) );
1668 - if ( ! $existing_app->have_posts() ) {
1617 + if (get_page_by_title('wpwBot Mobile App') == NULL) {
1669 1618 //post status and options
1670 1619 $app_page = array(
1671 1620 'comment_status' => 'closed',
1672 1621 'ping_status' => 'closed',
1673 1622 'post_author' => get_current_user_id(),
1674 - 'post_date' => gmdate('Y-m-d H:i:s'),
1623 + 'post_date' => date('Y-m-d H:i:s'),
1675 1624 'post_status' => 'publish',
1676 1625 'post_title' => 'wpwBot Mobile App',
1677 1626 'post_name' => 'wpwbot-mobile-app',
1678 1627 'post_type' => 'page',
@@ -1682,16 +1631,15 @@
1682 1631 //save the id in the database
1683 1632 update_option('wp_chatbot_app_checkout', $wpwbot_app);
1684 1633 }
1685 1634 //App checkout page create
1686 - $existing_checkout = new WP_Query( array( 'post_type' => 'page', 'name' => 'wpwbot-app-checkout', 'post_status' => 'publish', 'posts_per_page' => 1 ) );
1687 - if ( ! $existing_checkout->have_posts() ) {
1635 + if (get_page_by_title('wpwBot App Checkout') == NULL) {
1688 1636 //post status and options
1689 1637 $checkout_page = array(
1690 1638 'comment_status' => 'closed',
1691 1639 'ping_status' => 'closed',
1692 1640 'post_author' => get_current_user_id(),
1693 - 'post_date' => gmdate('Y-m-d H:i:s'),
1641 + 'post_date' => date('Y-m-d H:i:s'),
1694 1642 'post_status' => 'publish',
1695 1643 'post_title' => 'wpwBot App Checkout',
1696 1644 'post_name' => 'wpwbot-app-checkout',
1697 1645 'post_type' => 'page',
@@ -1701,16 +1649,15 @@
1701 1649 //save the id in the database
1702 1650 update_option('wp_chatbot_app_checkout', $app_checkout);
1703 1651 }
1704 1652 //App Order thank you page create
1705 - $existing_thankyou = new WP_Query( array( 'post_type' => 'page', 'name' => 'wpwbot-app-order-thankyou', 'post_status' => 'publish', 'posts_per_page' => 1 ) );
1706 - if ( ! $existing_thankyou->have_posts() ) {
1653 + if (get_page_by_title('wpwBot App Order Thank You') == NULL) {
1707 1654 //post status and options
1708 1655 $thankyou_page = array(
1709 1656 'comment_status' => 'closed',
1710 1657 'ping_status' => 'closed',
1711 1658 'post_author' => get_current_user_id(),
1712 - 'post_date' => gmdate('Y-m-d H:i:s'),
1659 + 'post_date' => date('Y-m-d H:i:s'),
1713 1660 'post_status' => 'publish',
1714 1661 'post_title' => 'wpwBot App Order Thank You',
1715 1662 'post_name' => 'wpwbot-app-order-thankyou',
1716 1663 'post_type' => 'page',
@@ -1721,9 +1668,9 @@
1721 1668 update_option('wp_chatbot_app_order_thankyou', $app_order_thankyou);
1722 1669 }
1723 1670 }
1724 1671 //Keep tracking from App by cookies
1725 - if ( isset( $_GET['from'] ) && sanitize_text_field( wp_unslash( $_GET['from'] ) ) === 'app' ) { // phpcs:ignore WordPress.Security.NonceVerification
1672 + if (isset($_GET['from']) && $_GET['from'] == 'app') {
1726 1673 if (!isset($_COOKIE['from_app'])) {
1727 1674 setcookie('from_app', 'yes', (time() + 3600), '/');
1728 1675 }
1729 1676 }
@@ -1737,9 +1684,9 @@
1737 1684 global $wp;
1738 1685 if (is_checkout() && !empty($wp->query_vars['order-received'])) {
1739 1686 $thanks_page_id = get_option('wp_chatbot_app_order_thankyou');
1740 1687 $thanks_parmanlink = esc_url(get_permalink($thanks_page_id));
1741 - wp_safe_redirect($thanks_parmanlink . '?order_id=' . $order_get_id);
1688 + wp_redirect($thanks_parmanlink . '?order_id=' . $order_get_id);
1742 1689 exit;
1743 1690 }
1744 1691 } else {
1745 1692 remove_action('wpcommerce_thankyou', 'qcld_wb_chatbot__redirect_after_purchase');
@@ -1747,12 +1694,9 @@
1747 1694 }
1748 1695 }
1749 1696
1750 1697 function qcld_choose_random($array){
1751 - if (is_array($array) && !empty($array)) {
1752 - return $array[array_rand($array)];
1753 - }
1754 - return $array;
1698 + return $array[array_rand($array)];
1755 1699 }
1756 1700
1757 1701 //User session count
1758 1702 add_action('wp_ajax_qcld_wb_chatbot_session_count', 'qcld_wb_chatbot_session_count');
@@ -1758,9 +1702,8 @@
1758 1702 add_action('wp_ajax_qcld_wb_chatbot_session_count', 'qcld_wb_chatbot_session_count');
1759 1703 add_action('wp_ajax_nopriv_qcld_wb_chatbot_session_count', 'qcld_wb_chatbot_session_count');
1760 1704 function qcld_wb_chatbot_session_count(){
1761 1705 // Nonce is checked, get the POST data and sign user on
1762 - check_ajax_referer( 'wp_chatbot', 'nonce' );
1763 1706 global $wpdb;
1764 1707 $wpdb->show_errors = true;
1765 1708 $tableuser = $wpdb->prefix.'wpbot_sessions';
1766 1709 $response = array();
@@ -1765,22 +1708,22 @@
1765 1708 $tableuser = $wpdb->prefix.'wpbot_sessions';
1766 1709 $response = array();
1767 1710
1768 1711
1769 - $session_exists = $wpdb->get_row($wpdb->prepare("select * from {$tableuser} where 1 and id = %d",1)); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, PluginCheck.Security.DirectDB.UnescapedDBParameter
1712 + $session_exists = $wpdb->get_row($wpdb->prepare("select * from $tableuser where 1 and id = %d",1)); //DB Call OK, No Caching OK
1770 1713
1771 1714 if(empty($session_exists)){
1772 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
1715 + $wpdb->insert(
1773 1716 $tableuser,
1774 1717 array(
1775 1718 'session' => 1,
1776 1719 )
1777 - );
1720 + ); //DB Call OK, No Caching OK
1778 1721 }else{
1779 1722
1780 1723 $session_id = $session_exists->id;
1781 1724
1782 - $wpdb->update( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1725 + $wpdb->update(
1783 1726 $tableuser,
1784 1727 array(
1785 1728 'session'=>($session_exists->session+1),
1786 1729 ),
@@ -1788,9 +1731,9 @@
1788 1731 array(
1789 1732 '%d',
1790 1733 ),
1791 1734 array('%d')
1792 - );
1735 + ); //DB Call OK, No Caching OK
1793 1736
1794 1737 }
1795 1738
1796 1739 wp_send_json($response);
@@ -1798,9 +1741,9 @@
1798 1741
1799 1742 /* WPBot Chat History Addon check */
1800 1743 function qcld_wpbot_is_active_chat_history(){
1801 1744
1802 - if(function_exists('qcwp_chat_session_menu_fnc') || function_exists('qcwp_chat_session_menu_fnc_free') || function_exists( 'qcpdcs_chat_session_menu_fnc' ) ){
1745 + if(function_exists('qcwp_chat_session_menu_fnc') || function_exists( 'qcpdcs_chat_session_menu_fnc' ) ){
1803 1746 return 1;
1804 1747 }else{
1805 1748 return 0;
1806 1749 }
@@ -1815,11 +1758,9 @@
1815 1758 return $data;
1816 1759 }
1817 1760 add_action('wp_ajax_qcld_small_talk_import', 'qcld_small_talk_import');
1818 1761 function qcld_small_talk_import(){
1819 - if ( ! current_user_can( 'manage_options' ) ) {
1820 - wp_die();
1821 - }
1762 +
1822 1763 global $wpdb;
1823 1764
1824 1765 $table = $wpdb->prefix.'wpbot_response';
1825 1766
@@ -1826,10 +1767,9 @@
1826 1767 $csvFile = file(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . 'small_talk.csv');
1827 1768
1828 1769 foreach ($csvFile as $line) {
1829 1770 $line = str_getcsv($line, ',', '"');
1830 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
1831 - $table, array(
1771 + $wpdb->insert($table, array(
1832 1772 'query' => $line[0],
1833 1773 'keyword' => $line[1],
1834 1774 'response' => $line[2],
1835 1775 'category'=> $line[3],
@@ -1834,17 +1774,16 @@
1834 1774 'response' => $line[2],
1835 1775 'category'=> $line[3],
1836 1776 'intent'=> '',
1837 1777 //'lang'=> 'en_US',
1838 - ));
1778 + )); //DB Call OK, No Caching OK
1839 1779 }
1840 1780
1841 1781 $table2 = $wpdb->prefix.'wpbot_response_category';
1842 1782
1843 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
1844 - $table2, array(
1783 + $wpdb->insert($table2, array(
1845 1784 'name' => 'smalltalk',
1846 - ));
1785 + )); //DB Call OK, No Caching OK
1847 1786
1848 1787 update_option( 'qcld_small_talk_imported', 'yes' );
1849 1788
1850 1789 }
@@ -1872,15 +1811,11 @@
1872 1811 function qcld_change_language_from_center() {
1873 1812 if ( ! current_user_can( 'manage_options' ) ) {
1874 1813 wp_send_json_error( array( 'message' => 'Unauthorized.' ) );
1875 1814 }
1876 - $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( wp_unslash( $_POST['nonce'] ) ) : '';
1877 - if ( ! wp_verify_nonce( $nonce, 'wp_chatbot' ) ) {
1878 - wp_send_json_error( array( 'message' => 'Invalid nonce.' ) );
1879 - }
1880 1815 $plugin_path = plugin_dir_path( __FILE__ );
1881 1816 include $plugin_path . 'includes/admin/settings-fields.php';
1882 - $json_file_path = $plugin_path . 'includes/language-center.json';
1817 + $json_file_path = $plugin_path . 'includes/language center.json'; // Adjust path as needed
1883 1818
1884 1819 $json_string = file_get_contents( $json_file_path );
1885 1820 if ( isset( $_POST['language'] ) ) {
1886 1821 $language = sanitize_text_field( wp_unslash( $_POST['language'] ) );
@@ -1891,5 +1826,5 @@
1891 1826 wp_send_json_error( array( 'message' => 'Language not specified.' ) );
1892 1827
1893 1828 }
1894 1829 }
1895 -}
1830 +}