PluginProbe
WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services / 7.8.7
WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services v7.8.7
8.7.8 8.7.7 8.7.6 8.7.5 8.7.4 8.7.3 8.7.2 8.7.1 8.7.0 8.6.9 8.6.8 8.6.7 8.6.6 8.6.5 8.6.4 8.6.2 8.6.1 8.6.0 8.5.9 8.5.8 8.5.7 8.5.6 8.5.5 8.5.4 8.5.3 All 534 releases
← All changes | functions.php +76 -288 8.7.57.8.7 View file →
@@ -14,9 +14,9 @@
14 14 $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_agent_image');
15 15 } else {
16 16 $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . 'custom-agent.png';
17 17 }
18 - $hidden_field = '<a class="wp-chatbot qc_wpbot_chat_link" id="wp-chatbot-search-btn" data-search-type="product" data-search-term="" style="max-height: 50px; margin-left: 10px;padding: 0 !important;position: absolute;top: -9px;right: -60px;"><img src="'. esc_url($wp_chatbot_custom_agent_path) .'" alt=""></a>';
18 + $hidden_field = '<a class="wp-chatbot qc_wpbot_chat_link" id="wp-chatbot-search-btn" data-search-type="product" data-search-term="" style="max-height: 50px; margin-left: 10px;padding: 0 !important;position: absolute;top: -9px;right: -60px;"><img src="'. esc_attr($wp_chatbot_custom_agent_path) .'" alt=""></a>';
19 19 $block_content = str_replace( '</form>', $hidden_field . '</form>', $form );
20 20 return $block_content;
21 21 }
22 22 if(get_option('wpbot_enable_on_search') == 1 && (get_option('disable_floating_button') != '1') && get_option('disable_wp_chatbot') != 1 ){
@@ -33,9 +33,9 @@
33 33 $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_agent_image');
34 34 } else {
35 35 $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . 'custom-agent.png';
36 36 }
37 - $hidden_field = '<button type="button" class="wp-chatbot qc_wpbot_chat_link" id="wp-chatbot-search-btn" data-search-type="product" data-search-term="" style="max-height: 50px; margin-left: 10px;padding: 0 !important"><img src="'. esc_url($wp_chatbot_custom_agent_path) .'" alt=""></button>';
37 + $hidden_field = '<button type="button" class="wp-chatbot qc_wpbot_chat_link" id="wp-chatbot-search-btn" data-search-type="product" data-search-term="" style="max-height: 50px; margin-left: 10px;padding: 0 !important"><img src="'. esc_attr($wp_chatbot_custom_agent_path) .'" alt=""></button>';
38 38 // Inject the hidden field before the closing </form> tag
39 39 $block_content = str_replace( '</div></form>', $hidden_field . '</div></form>', $block_content );
40 40 return $block_content;
41 41 }
@@ -58,62 +58,8 @@
58 58 });
59 59 </script>
60 60 <?php
61 61 }
62 -/**
63 - * Extract a YouTube video ID from common URL formats.
64 - *
65 - * @param string $url YouTube watch, embed, short, or youtu.be URL.
66 - * @return string Video ID or empty string.
67 - */
68 -if ( ! function_exists( 'qcld_wpbot_extract_youtube_id' ) ) {
69 - function qcld_wpbot_extract_youtube_id( $url ) {
70 - $url = trim( (string) $url );
71 - if ( $url === '' ) {
72 - return '';
73 - }
74 -
75 - if ( preg_match( '/(?:youtube\.com\/(?:embed\/|shorts\/|live\/|watch\?(?:.*&)?v=)|youtu\.be\/)([A-Za-z0-9_-]{11})/', $url, $matches ) ) {
76 - return $matches[1];
77 - }
78 -
79 - $path = (string) wp_parse_url( $url, PHP_URL_PATH );
80 - $base = basename( $path );
81 - if ( preg_match( '/^[A-Za-z0-9_-]{11}$/', $base ) ) {
82 - return $base;
83 - }
84 -
85 - return '';
86 - }
87 -}
88 -if ( ! function_exists( 'qcld_wpbot_youtube_icon_embed_src' ) ) {
89 - function qcld_wpbot_youtube_icon_embed_src( $url ) {
90 - $video_id = qcld_wpbot_extract_youtube_id( $url );
91 - if ( $video_id === '' ) {
92 - return '';
93 - }
94 -
95 - return add_query_arg(
96 - array(
97 - 'autoplay' => '1',
98 - 'mute' => '1',
99 - 'loop' => '1',
100 - 'playlist' => $video_id,
101 - 'controls' => '0',
102 - 'showinfo' => '0',
103 - 'rel' => '0',
104 - 'fs' => '0',
105 - 'iv_load_policy' => '3',
106 - 'cc_load_policy' => '0',
107 - 'disablekb' => '1',
108 - 'playsinline' => '1',
109 - 'modestbranding' => '1',
110 - 'color' => 'white',
111 - ),
112 - 'https://www.youtube.com/embed/' . rawurlencode( $video_id )
113 - );
114 - }
115 -}
116 62 function wp_chatbot_load_footer_html(){
117 63 if ( get_option('disable_wp_chatbot') != 1 && wp_chatbot_load_controlling() === true) {
118 64
119 65 ?>
@@ -119,9 +65,9 @@
119 65 ?>
120 66 <style>
121 67 <?php if(get_option('wp_chatbot_custom_css')!="") {
122 68
123 - echo wp_strip_all_tags( get_option('wp_chatbot_custom_css') );// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
69 + echo get_option('wp_chatbot_custom_css');
124 70 }
125 71 ?>
126 72 </style>
127 73
@@ -133,27 +79,10 @@
133 79 }
134 80 ?>
135 81 <style>
136 82 .wp-chatbot-container {
137 - background-color: #eceef3 !important;
138 83 background-image: url(<?php echo esc_url($qcld_wb_chatbot_board_bg_path); ?>) !important;
139 - background-size: cover !important;
140 - background-position: center !important;
141 - background-repeat: no-repeat !important;
142 84 }
143 - .wp-chatbot-template-01 #wp-chatbot-board-container,
144 - .wp-chatbot-template-01 .wp-chatbot-board-container {
145 - background-color: #eceef3 !important;
146 - background-image: none !important;
147 - }
148 - .wp-chatbot-template-01 #wp-chatbot-board-container::before,
149 - .wp-chatbot-template-01 .wp-chatbot-board-container::before {
150 - background-color: #eceef3 !important;
151 - background-image: url(<?php echo esc_url($qcld_wb_chatbot_board_bg_path); ?>) !important;
152 - background-size: cover !important;
153 - background-position: center !important;
154 - background-repeat: no-repeat !important;
155 - }
156 85 </style>
157 86 <?php }
158 87 $wp_chatbot_enable_rtl = "";
159 88 if (get_option('enable_wp_chatbot_rtl') == '1') {
@@ -226,9 +155,9 @@
226 155 }
227 156 ?>
228 157 <div class="wp-chatbot-notification-agent-profile">
229 158 <div class="wp-chatbot-notification-widget-avatar" ><img
230 - src="<?php echo esc_url($wp_chatbot_custom_agent_path); ?>" alt=""></div>
159 + src="<?php echo esc_attr($wp_chatbot_custom_agent_path); ?>" alt=""></div>
231 160 <div class="wp-chatbot-notification-welcome"><?php echo wp_kses_post(wpb_randmom_message_handle(maybe_unserialize(get_option('qlcd_wp_chatbot_welcome')))) . ' <strong>' . esc_html(get_option('qlcd_wp_chatbot_host')) . '</strong>'; ?></div>
232 161 </div>
233 162 <?php
234 163 //update_option('qlcd_wp_chatbot_notifications','Welcome to WpBot');
@@ -251,72 +180,14 @@
251 180 $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_icon');
252 181 } else {
253 182 $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . 'custom.png';
254 183 }
255 - $_wpbot_icon_video = get_option('wp_chatbot_icon_video', '');
256 - $_wpbot_video_is_youtube = ( strpos( $_wpbot_icon_video, 'youtube.com' ) !== false || strpos( $_wpbot_icon_video, 'youtu.be' ) !== false );
257 - $_wpbot_youtube_embed_src = $_wpbot_video_is_youtube ? qcld_wpbot_youtube_icon_embed_src( $_wpbot_icon_video ) : '';
258 - $_wpbot_video_delay_ms = absint( get_option( 'wp_chatbot_icon_video_delay', 0 ) ) * 1000;
259 -
260 - $wp_chatbot_ball_is_youtube = ($_wpbot_icon_video !== '' && (strpos($_wpbot_icon_video, 'youtube.com') !== false || strpos($_wpbot_icon_video, 'youtu.be') !== false));
261 - $wp_chatbot_ball_is_video = ($_wpbot_icon_video !== '' && !$wp_chatbot_ball_is_youtube);
262 - $wp_chatbot_ball_has_video = ($wp_chatbot_ball_is_youtube || $wp_chatbot_ball_is_video);
263 184 ?>
264 185 <img src="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>"
265 - alt="wpChatIcon" qcld_agent="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>"
266 - id="wp-chatbot-ball-icon-img"
267 - <?php if ($wp_chatbot_ball_has_video) { echo 'style="display:none;"'; } ?> >
268 - <?php if ( $_wpbot_icon_video !== '' ) : ?>
269 - <?php if ( $_wpbot_video_is_youtube && $_wpbot_youtube_embed_src !== '' ) : ?>
270 - <iframe class="wpbot-icon-video" src="<?php echo $_wpbot_video_delay_ms > 0 ? 'about:blank' : esc_url( $_wpbot_youtube_embed_src ); ?>" data-wpbot-yt-src="<?php echo esc_url( $_wpbot_youtube_embed_src ); ?>" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture"></iframe>
271 - <?php elseif ( ! $_wpbot_video_is_youtube ) : ?>
272 - <video class="wpbot-icon-video" src="<?php echo esc_url( $_wpbot_icon_video ); ?>" autoplay muted loop playsinline preload="auto"></video>
273 - <?php endif; ?>
274 - <?php endif; ?>
186 + alt="wpChatIcon" qcld_agent="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>" >
187 +
275 188 </div>
276 -
277 189 </div>
278 - <?php
279 - if ( $_wpbot_icon_video !== '' ) :
280 - ?>
281 - <script>
282 - (function(){
283 - var wpbotDelay = <?php echo (int) $_wpbot_video_delay_ms; ?>;
284 - function wpbotForcePlay(){
285 - var v = document.querySelector('#wp-chatbot-ball video.wpbot-icon-video');
286 - if( v ){
287 - v.muted = true;
288 - v.volume = 0;
289 - v.loop = true;
290 - var tries = 0, maxTries = 30;
291 - var timer = setInterval(function(){
292 - tries++;
293 - v.play().then(function(){ clearInterval(timer); }).catch(function(){});
294 - if( tries >= maxTries ) clearInterval(timer);
295 - }, 300);
296 - }
297 - var yt = document.querySelector('#wp-chatbot-ball iframe.wpbot-icon-video');
298 - if( yt ){
299 - var ytSrc = yt.getAttribute('data-wpbot-yt-src');
300 - if( ytSrc && ( !yt.getAttribute('src') || yt.getAttribute('src') === 'about:blank' || yt.getAttribute('src').indexOf('autoplay=1') === -1 ) ){
301 - yt.setAttribute('src', ytSrc);
302 - }
303 - }
304 - }
305 - function wpbotDelayedPlay(){
306 - setTimeout(wpbotForcePlay, wpbotDelay);
307 - }
308 - if( document.readyState === 'loading' ){
309 - document.addEventListener('DOMContentLoaded', wpbotDelayedPlay);
310 - } else {
311 - wpbotDelayedPlay();
312 - }
313 - window.addEventListener('load', function(){
314 - setTimeout(wpbotForcePlay, wpbotDelay);
315 - });
316 - })();
317 - </script>
318 - <?php endif; ?>
319 190 <?php
320 191 $fb_app_id = get_option('qlcd_wp_chatbot_fb_app_id');
321 192 $fb_page_id = get_option('qlcd_wp_chatbot_fb_page_id');
322 193 $fb_mgs_color = get_option('qlcd_wp_chatbot_fb_color') != '' ? get_option('qlcd_wp_chatbot_fb_color') : '#0084ff';
@@ -442,10 +313,10 @@
442 313 }
443 314 }
444 315 //Checking wpwbot opening hour
445 316 function wp_chatbot_check_opening_hours(){
446 - $curent_day=strtolower(gmdate('l',strtotime(current_time( 'mysql' ))));
447 - $current_time=gmdate('H:i',strtotime(current_time( 'mysql')));
317 + $curent_day=strtolower(date('l',strtotime(current_time( 'mysql' ))));
318 + $current_time=date('H:i',strtotime(current_time( 'mysql')));
448 319 $is_wpwbot_open =false;
449 320 if(get_option('wpwbot_hours')) {
450 321 $wpwbot_times = wp_kses_post(unserialize(get_option('wpwbot_hours')));
451 322 if (isset($wpwbot_times[$curent_day])) {
@@ -467,16 +338,9 @@
467 338 */
468 339 add_action('wp_ajax_qcld_wb_chatbot_keyword', 'qcld_wb_chatbot_keyword');
469 340 add_action('wp_ajax_nopriv_qcld_wb_chatbot_keyword', 'qcld_wb_chatbot_keyword');
470 341 function qcld_wb_chatbot_keyword(){
471 - // Verify nonce for security
472 - $nonce = isset($_POST['security']) ? sanitize_text_field(wp_unslash($_POST['security'])) : (isset($_POST['nonce']) ? sanitize_text_field(wp_unslash($_POST['nonce'])) : '');
473 - if ( ! wp_verify_nonce( $nonce, 'wp_chatbot' ) && ! wp_verify_nonce( $nonce, 'qcsecretbotnonceval123qc' ) ) {
474 - wp_send_json_error( array( 'status' => 'fail', 'message' => 'Security check failed.' ) );
475 - wp_die();
476 - }
477 -
478 - $keyword = sanitize_text_field(wp_unslash($_POST['keyword']));
342 + $keyword = sanitize_text_field($_POST['keyword']);
479 343 $product_per_page = get_option('qlcd_wp_chatbot_ppp') != '' ? get_option('qlcd_wp_chatbot_ppp') : 10;
480 344 if (get_option('qlcd_wp_chatbot_search_option') == 'standard') {
481 345 $product_orderby = sanitize_text_field(get_option('qlcd_wp_chatbot_product_orderby') != '' ? get_option('qlcd_wp_chatbot_product_orderby') : 'title');
482 346 $product_order = sanitize_text_field(get_option('qlcd_wp_chatbot_product_order') != '' ? get_option('qlcd_wp_chatbot_product_order') : 'ASC');
@@ -522,9 +386,9 @@
522 386 endwhile;
523 387 wp_reset_postdata();
524 388 $html .= '</ul>';
525 389 if ($total_product_num > $product_per_page && $product_per_page > 0 ) {
526 - $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . esc_attr($keyword) . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
390 + $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . $keyword . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
527 391 }
528 392 }
529 393 $html .= '</div>';
530 394 } else if (get_option('qlcd_wp_chatbot_search_option') == 'advanced') {
@@ -552,9 +416,9 @@
552 416 }
553 417 }
554 418 $html .= '</ul>';
555 419 if ($total_product_num > $product_per_page && $product_per_page > 0) {
556 - $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . esc_attr($more_product_ids) . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
420 + $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . $more_product_ids . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
557 421 }
558 422 }
559 423 $html .= '</div>';
560 424 }
@@ -569,15 +433,16 @@
569 433 add_action('wp_ajax_nopriv_qcld_wb_chatbot_category', 'qcld_wb_chatbot_category');
570 434 function qcld_wb_chatbot_category(){
571 435 $category_type="common";
572 436 if (get_option('wp_chatbot_show_parent_category') != "") {
573 - $terms = get_terms( array( 'taxonomy' => 'product_cat', 'parent' => 0, 'hide_empty' => true, 'fields' => 'all' ) );
437 + $terms = get_terms('product_cat', array('parent' => 0, 'hide_empty' => true, 'fields' => 'all'));
438 +
574 439 } else {
575 - $terms = get_terms( array( 'taxonomy' => 'product_cat', 'hide_empty' => true, 'fields' => 'all' ) );
440 + $terms = get_terms('product_cat', array('hide_empty' => true, 'fields' => 'all'));
576 441 }
577 442 $html = "";
578 443 foreach ($terms as $term) {
579 - $child_terms=get_terms( array( 'taxonomy' => 'product_cat', 'parent' => $term->term_id, 'hide_empty' => true, 'fields' => 'all' ) );
444 + $child_terms=get_terms('product_cat', array('parent' => $term->term_id, 'hide_empty' => true, 'fields' => 'all'));
580 445 if(get_option('wp_chatbot_show_sub_category')==1 && count($child_terms) >0){
581 446 $category_type="hasChilds";
582 447 }
583 448 $html .= '<span class="qcld-chatbot-product-category" data-category-type="' . $category_type . '" data-category-slug="' . $term->slug . '" data-category-id="' . $term->term_id . '">' . $term->name . '</span>';
@@ -590,10 +455,10 @@
590 455 */
591 456 add_action('wp_ajax_qcld_wb_chatbot_sub_category', 'qcld_wb_chatbot_sub_category');
592 457 add_action('wp_ajax_nopriv_qcld_wb_chatbot_sub_category', 'qcld_wb_chatbot_sub_category');
593 458 function qcld_wb_chatbot_sub_category(){
594 - $parent_id = intval( wp_unslash( $_POST['parent_id'] ) );
595 - $terms = get_terms( array( 'taxonomy' => 'product_cat', 'parent' => $parent_id, 'hide_empty' => true, 'fields' => 'all' ) );
459 + $parent_id = stripslashes($_POST['parent_id']);
460 + $terms = get_terms('product_cat', array('parent' => $parent_id, 'hide_empty' => true, 'fields' => 'all'));
596 461 $html = "";
597 462 foreach ($terms as $term) {
598 463 $html .= '<span class="qcld-chatbot-product-category" data-category-type="common" data-category-slug="' . $term->slug . '" data-category-id="' . $term->term_id . '">' . $term->name . '</span>';
599 464 }
@@ -605,9 +470,9 @@
605 470 */
606 471 add_action('wp_ajax_qcld_wb_chatbot_category_products', 'qcld_wb_chatbot_category_products');
607 472 add_action('wp_ajax_nopriv_qcld_wb_chatbot_category_products', 'qcld_wb_chatbot_category_products');
608 473 function qcld_wb_chatbot_category_products(){
609 - $category_id = intval( wp_unslash( $_POST['category'] ) );
474 + $category_id = stripslashes($_POST['category']);
610 475 $product_per_page = sanitize_text_field(get_option('qlcd_wp_chatbot_ppp') != '' ? get_option('qlcd_wp_chatbot_ppp') : 10);
611 476 $product_orderby = sanitize_text_field(get_option('qlcd_wp_chatbot_product_orderby') != '' ? get_option('qlcd_wp_chatbot_product_orderby') : 'title');
612 477 $product_order = sanitize_text_field(get_option('qlcd_wp_chatbot_product_order') != '' ? get_option('qlcd_wp_chatbot_product_order') : 'ASC');
613 478 //Merging all query together.
@@ -844,11 +709,11 @@
844 709 //load more
845 710 add_action('wp_ajax_qcld_wb_chatbot_load_more', 'qcld_wb_chatbot_load_more');
846 711 add_action('wp_ajax_nopriv_qcld_wb_chatbot_load_more', 'qcld_wb_chatbot_load_more');
847 712 function qcld_wb_chatbot_load_more(){
848 - $offset = intval( wp_unslash( $_POST['offset'] ) );
849 - $search_type = sanitize_text_field( wp_unslash( $_POST['search_type'] ) );
850 - $search_term = sanitize_text_field( wp_unslash( $_POST['search_term'] ) );
713 + $offset = stripslashes($_POST['offset']);
714 + $search_type = stripslashes($_POST['search_type']);
715 + $search_term = stripslashes($_POST['search_term']);
851 716 $product_per_page = sanitize_text_field(get_option('qlcd_wp_chatbot_ppp') != '' ? get_option('qlcd_wp_chatbot_ppp') : 10);
852 717 $product_orderby = sanitize_text_field(get_option('qlcd_wp_chatbot_product_orderby') != '' ? get_option('qlcd_wp_chatbot_product_orderby') : 'title');
853 718 $product_order = sanitize_text_field(get_option('qlcd_wp_chatbot_product_order') != '' ? get_option('qlcd_wp_chatbot_product_order') : 'ASC');
854 719 $next_offset = intval($product_per_page + $offset);
@@ -979,9 +844,9 @@
979 844 //product details
980 845 add_action('wp_ajax_qcld_wb_chatbot_product_details', 'qcld_wb_chatbot_product_details');
981 846 add_action('wp_ajax_nopriv_qcld_wb_chatbot_product_details', 'qcld_wb_chatbot_product_details');
982 847 function qcld_wb_chatbot_product_details(){
983 - $product_id = intval( wp_unslash( $_POST['wp_chatbot_pid'] ) );
848 + $product_id = stripslashes($_POST['wp_chatbot_pid']);
984 849 //Tracking product view from chat board
985 850 wp_chatbot_view_track_product_by_id($product_id);
986 851 //wpcommerce product factory
987 852 $wc_pf = new WC_Product_Factory();
@@ -1054,11 +919,10 @@
1054 919 $variations .= '<label for="' . sanitize_title($name) . '">' . $title . '</label>';
1055 920 $variations .= '<select id="' . esc_attr(sanitize_title($name)) . '" name="attribute_' . sanitize_title($name) . '" data-attribute_name="attribute_' . sanitize_title($name) . '" class="each_attribute">';
1056 921 $variations .= '<option value="">' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_choose_option')))) . '</option>';
1057 922 foreach ($values as $value) {
1058 - $attr_key = 'attribute_' . sanitize_title( $name );
1059 - if ( isset( $_REQUEST[ $attr_key ] ) ) { // phpcs:ignore WordPress.Security.NonceVerification
1060 - $selected_value = sanitize_text_field( wp_unslash( $_REQUEST[ $attr_key ] ) );
923 + if (isset($_REQUEST['attribute_' . sanitize_title($name)])) {
924 + $selected_value = $_REQUEST['attribute_' . sanitize_title($name)];
1061 925 } else {
1062 926 $selected_value = '';
1063 927 }
1064 928 $variations .= '<option value="' . esc_attr(strtolower($value)) . '"' . selected($selected_value, $value, false) . '>' . apply_filters('wpcommerce_variation_option_name', $value) . '</option>';
@@ -1082,12 +946,12 @@
1082 946 //Add to cart for variable product.
1083 947 add_action('wp_ajax_qcld_variable_add_to_cart', 'qcld_variable_add_to_cart');
1084 948 add_action('wp_ajax_nopriv_qcld_variable_add_to_cart', 'qcld_variable_add_to_cart');
1085 949 function qcld_variable_add_to_cart(){
1086 - $product_id = intval( wp_unslash( $_POST['p_id'] ) );
1087 - $quantity = intval( wp_unslash( $_POST['quantity'] ) );
1088 - $variations_id = intval( wp_unslash( $_POST['variations_id'] ) );
1089 - $attrs = isset( $_POST['attributes'] ) ? array_map( 'sanitize_text_field', wp_unslash( (array) $_POST['attributes'] ) ) : array();
950 + $product_id = stripslashes($_POST['p_id']);
951 + $quantity = stripslashes($_POST['quantity']);
952 + $variations_id = stripslashes($_POST['variations_id']);
953 + $attrs = stripslashes($_POST['attributes']);
1090 954 //echo wp_send_json(array('p_id'=>$product_id,'qnty'=>$quantity,'id'=>$variations_id,'att'=>$attrs));
1091 955 $attributes = array();
1092 956 foreach ($attrs as $attr) {
1093 957 $single = explode("#", $attr);
@@ -1107,10 +971,10 @@
1107 971 //Add to cart for simple product.
1108 972 add_action('wp_ajax_qcld_wb_chatbot_add_to_cart', 'qcld_wb_chatbot_add_to_cart');
1109 973 add_action('wp_ajax_nopriv_qcld_wb_chatbot_add_to_cart', 'qcld_wb_chatbot_add_to_cart');
1110 974 function qcld_wb_chatbot_add_to_cart(){
1111 - $product_id = intval( wp_unslash( $_POST['product_id'] ) );
1112 - $product_quantity = intval( wp_unslash( $_POST['quantity'] ) );
975 + $product_id = stripslashes($_POST['product_id']);
976 + $product_quantity = stripslashes($_POST['quantity']);
1113 977 global $wpcommerce;
1114 978 $result = $wpcommerce->cart->add_to_cart($product_id, $product_quantity);
1115 979 if ($result != false) {
1116 980 wp_send_json('simple');
@@ -1121,19 +985,15 @@
1121 985 //Support part
1122 986 add_action('wp_ajax_qcld_wb_chatbot_support_email', 'qcld_wb_chatbot_support_email');
1123 987 add_action('wp_ajax_nopriv_qcld_wb_chatbot_support_email', 'qcld_wb_chatbot_support_email');
1124 988 function qcld_wb_chatbot_support_email(){
1125 - $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( wp_unslash( $_POST['nonce'] ) ) : '';
1126 - if ( ! wp_verify_nonce( $nonce, 'qcsecretbotnonceval123qc' ) ) {
1127 - wp_send_json_error( array( 'error' => esc_html__( 'Error: Invalid nonce verification.', 'chatbot' ) ) );
1128 - }
1129 - $name = trim(sanitize_text_field(wp_unslash($_POST['name'])));
1130 - $email = sanitize_email(wp_unslash($_POST['email']));
1131 - $message = sanitize_text_field(wp_unslash($_POST['message']));
989 + $name = trim(sanitize_text_field($_POST['name']));
990 + $email = sanitize_email($_POST['email']);
991 + $message = sanitize_text_field($_POST['message']);
1132 992 $subject = sanitize_text_field(get_option('qlcd_wp_chatbot_email_sub') != '' ? get_option('qlcd_wp_chatbot_email_sub') : 'Support Email from wpWBot by Client');
1133 993 //Extract Domain
1134 994 $url = get_site_url();
1135 - $url = wp_parse_url($url);
995 + $url = parse_url($url);
1136 996 $domain = $url['host'];
1137 997 //$admin_email = "admin@" . $domain;
1138 998 $admin_email = sanitize_email(get_option('admin_email'));
1139 999 $toEmail = sanitize_email(get_option('qlcd_wp_chatbot_admin_email') != '' ? get_option('qlcd_wp_chatbot_admin_email') : $admin_email);
@@ -1143,8 +1003,9 @@
1143 1003 $fromEmail = get_option('qlcd_wp_chatbot_from_email');
1144 1004 }else{
1145 1005 $fromEmail = "wordpress@" . $domain;
1146 1006 }
1007 +
1147 1008 //Starting messaging and status.
1148 1009 $response['status'] = 'fail';
1149 1010 $response['message'] = str_replace('\\', '',wp_kses_post(get_option('qlcd_wp_chatbot_email_fail')));
1150 1011 if (filter_var($email, FILTER_VALIDATE_EMAIL) === false) {
@@ -1178,15 +1039,14 @@
1178 1039 //Support Phone
1179 1040 add_action('wp_ajax_qcld_wb_chatbot_support_phone', 'qcld_wb_chatbot_support_phone');
1180 1041 add_action('wp_ajax_nopriv_qcld_wb_chatbot_support_phone', 'qcld_wb_chatbot_support_phone');
1181 1042 function qcld_wb_chatbot_support_phone(){
1182 - check_ajax_referer('qcsecretbotnonceval123qc', 'nonce');
1183 - $name = trim(sanitize_text_field(wp_unslash($_POST['name'])));
1184 - $phone =sanitize_text_field(wp_unslash($_POST['phone']));
1043 + $name = trim(sanitize_text_field($_POST['name']));
1044 + $phone =sanitize_text_field($_POST['phone']);
1185 1045 $subject = 'WPBot Support Mail Request for Call Back';
1186 1046 //Extract Domain
1187 1047 $url = get_site_url();
1188 - $url = wp_parse_url($url);
1048 + $url = parse_url($url);
1189 1049 $domain = $url['host'];
1190 1050 //$admin_email = "admin@" . $domain;
1191 1051 $admin_email = get_option('admin_email');
1192 1052 $toEmail = sanitize_email(get_option('qlcd_wp_chatbot_admin_email') != '' ? get_option('qlcd_wp_chatbot_admin_email') : $admin_email);
@@ -1224,9 +1084,9 @@
1224 1084 }
1225 1085 // Order Status part. removed
1226 1086
1227 1087 function wpb_randmom_message_handle($items){
1228 - return $items[wp_rand(0, count($items) - 1)];
1088 + return $items[rand(0, count($items) - 1)];
1229 1089 }
1230 1090 function qcld_wb_chatbot_func_str_replace($messages = array()){
1231 1091 $refined_mesgses = array();
1232 1092 foreach ($messages as $message) {
@@ -1241,10 +1101,10 @@
1241 1101 // First check the nonce, if it fails the function will break
1242 1102 check_ajax_referer('wpwbot-order-nonce', 'security');
1243 1103 // Nonce is checked, get the POST data and sign user on
1244 1104 $info = array();
1245 - $info['user_login'] = trim(sanitize_text_field(wp_unslash($_POST['user_name'])));
1246 - $info['user_password'] = trim(sanitize_text_field(wp_unslash($_POST['user_pass'])));
1105 + $info['user_login'] = trim(sanitize_text_field($_POST['user_name']));
1106 + $info['user_password'] = trim(sanitize_text_field($_POST['user_pass']));
1247 1107 $info['remember'] = true;
1248 1108 $user_signon = wp_signon($info, false);
1249 1109 $response = array();
1250 1110 if (is_wp_error($user_signon)) {
@@ -1300,9 +1160,9 @@
1300 1160 $order_url = '<a href="' . get_url(get_permalink(get_option('wpcommerce_myaccount_page_id')) . '/view-order/' . $order->ID) . '" target="_blank" >' . $order->ID . '</a>';
1301 1161 }
1302 1162 $order_html .= '<div class="wp-chatbot-orders-single">
1303 1163 <div class="order-id"> ' . $order_url . '</div>
1304 - <div class="order-date"> <p>' . gmdate("m/d/Y", strtotime($order->post_date)) . '</p> </div>
1164 + <div class="order-date"> <p>' . date("m/d/Y", strtotime($order->post_date)) . '</p> </div>
1305 1165 <div class="order-items">';
1306 1166 $singleOrder = new WC_Order($order->ID);
1307 1167 $items = $singleOrder->get_items();
1308 1168 foreach ($items as $item) {
@@ -1402,9 +1262,9 @@
1402 1262 $html .= get_the_post_thumbnail(get_the_ID(), 'shop_catalog') . '
1403 1263 <div class="wp-chatbot-product-summary">
1404 1264 <div class="wp-chatbot-product-table">
1405 1265 <div class="wp-chatbot-product-table-cell">
1406 - <h3 class="wp-chatbot-product-title">' . esc_html($product->post->post_title) . '</h3>
1266 + <h3 class="wp-chatbot-product-title">' . $product->post->post_title . '</h3>
1407 1267 <div class="price">' . $product->get_price_html() . '</div>';
1408 1268 $html .= ' </div>
1409 1269 </div>
1410 1270 </div></a>
@@ -1473,9 +1333,9 @@
1473 1333 $html .= get_the_post_thumbnail(get_the_ID(), 'shop_catalog') . '
1474 1334 <div class="wp-chatbot-product-summary">
1475 1335 <div class="wp-chatbot-product-table">
1476 1336 <div class="wp-chatbot-product-table-cell">
1477 - <h3 class="wp-chatbot-product-title">' . esc_html($product->post->post_title) . '</h3>
1337 + <h3 class="wp-chatbot-product-title">' . $product->post->post_title . '</h3>
1478 1338 <div class="price">' . $product->get_price_html() . '</div>';
1479 1339 $html .= ' </div>
1480 1340 </div>
1481 1341 </div></a>
@@ -1649,12 +1509,11 @@
1649 1509 //Updating the cart items.
1650 1510 add_action('wp_ajax_qcld_wb_chatbot_update_cart_item_number', 'qcld_wb_chatbot_update_cart_item_number');
1651 1511 add_action('wp_ajax_nopriv_qcld_wb_chatbot_update_cart_item_number', 'qcld_wb_chatbot_update_cart_item_number');
1652 1512 function qcld_wb_chatbot_update_cart_item_number(){
1653 - check_ajax_referer( 'wp_chatbot', 'nonce' );
1654 1513 //getting cart items n
1655 - $cart_item_key = sanitize_text_field(wp_unslash($_POST['cart_item_key']));
1656 - $qnty = sanitize_text_field(wp_unslash($_POST['qnty']));
1514 + $cart_item_key = sanitize_text_field($_POST['cart_item_key']);
1515 + $qnty = sanitize_text_field($_POST['qnty']);
1657 1516 global $wpcommerce;
1658 1517 $result = $wpcommerce->cart->set_quantity($cart_item_key, $qnty);
1659 1518 wp_send_json($result);
1660 1519 }
@@ -1661,11 +1520,10 @@
1661 1520 //Show item after removing from cart page.
1662 1521 add_action('wp_ajax_qcld_wb_chatbot_cart_item_remove', 'qcld_wb_chatbot_cart_item_remove');
1663 1522 add_action('wp_ajax_nopriv_qcld_wb_chatbot_cart_item_remove', 'qcld_wb_chatbot_cart_item_remove');
1664 1523 function qcld_wb_chatbot_cart_item_remove(){
1665 - check_ajax_referer( 'wp_chatbot', 'nonce' );
1666 1524 //getting cart items n
1667 - $cart_item_key = sanitize_text_field(wp_unslash($_POST['cart_item']));
1525 + $cart_item_key = sanitize_text_field($_POST['cart_item']);
1668 1526 global $wpcommerce;
1669 1527 $result = $wpcommerce->cart->remove_cart_item($cart_item_key);
1670 1528 wp_send_json($result);
1671 1529 }
@@ -1721,9 +1579,9 @@
1721 1579
1722 1580 if(class_exists('Qcformbuilder_Forms_Admin')){
1723 1581
1724 1582
1725 - $results = $wpdb->get_results($wpdb->prepare("SELECT * FROM ". $wpdb->prefix."wfb_forms WHERE type= %s",'primary')); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1583 + $results = $wpdb->get_results($wpdb->prepare("SELECT * FROM ". $wpdb->prefix."wfb_forms WHERE type= %s",'primary')); //DB Call OK, No Caching OK
1726 1584
1727 1585 if(!empty($results)){
1728 1586
1729 1587 foreach($results as $result){
@@ -1748,10 +1606,10 @@
1748 1606 // function qcld_wb_chatbot_checkout_user_login(){
1749 1607 // // Nonce is checked, get the POST data and sign user on
1750 1608 // $info = array();
1751 1609 // //$info['nonce'] = $_POST['nonce_val'];
1752 -// $info['user_login'] = trim(sanitize_text_field(wp_unslash($_POST['user_name'])));
1753 -// $info['user_password'] = trim(sanitize_text_field(wp_unslash($_POST['user_pass'])));
1610 +// $info['user_login'] = trim(sanitize_text_field($_POST['user_name']));
1611 +// $info['user_password'] = trim(sanitize_text_field($_POST['user_pass']));
1754 1612 // $info['remember'] = true;
1755 1613 // $user_signon = wp_signon($info, false);
1756 1614 // // $response=$info;
1757 1615 // $response = array();
@@ -1792,16 +1650,15 @@
1792 1650 add_action('init', 'wp_chatbot_create_app_checkout_thankyou_page');
1793 1651 function wp_chatbot_create_app_checkout_thankyou_page(){
1794 1652 if (get_option('wp_chatbot_app_pages') == 1) {
1795 1653 //Mobile App page create
1796 - $existing_app = new WP_Query( array( 'post_type' => 'page', 'name' => 'wpwbot-mobile-app', 'post_status' => 'publish', 'posts_per_page' => 1 ) );
1797 - if ( ! $existing_app->have_posts() ) {
1654 + if (get_page_by_title('wpwBot Mobile App') == NULL) {
1798 1655 //post status and options
1799 1656 $app_page = array(
1800 1657 'comment_status' => 'closed',
1801 1658 'ping_status' => 'closed',
1802 1659 'post_author' => get_current_user_id(),
1803 - 'post_date' => gmdate('Y-m-d H:i:s'),
1660 + 'post_date' => date('Y-m-d H:i:s'),
1804 1661 'post_status' => 'publish',
1805 1662 'post_title' => 'wpwBot Mobile App',
1806 1663 'post_name' => 'wpwbot-mobile-app',
1807 1664 'post_type' => 'page',
@@ -1811,16 +1668,15 @@
1811 1668 //save the id in the database
1812 1669 update_option('wp_chatbot_app_checkout', $wpwbot_app);
1813 1670 }
1814 1671 //App checkout page create
1815 - $existing_checkout = new WP_Query( array( 'post_type' => 'page', 'name' => 'wpwbot-app-checkout', 'post_status' => 'publish', 'posts_per_page' => 1 ) );
1816 - if ( ! $existing_checkout->have_posts() ) {
1672 + if (get_page_by_title('wpwBot App Checkout') == NULL) {
1817 1673 //post status and options
1818 1674 $checkout_page = array(
1819 1675 'comment_status' => 'closed',
1820 1676 'ping_status' => 'closed',
1821 1677 'post_author' => get_current_user_id(),
1822 - 'post_date' => gmdate('Y-m-d H:i:s'),
1678 + 'post_date' => date('Y-m-d H:i:s'),
1823 1679 'post_status' => 'publish',
1824 1680 'post_title' => 'wpwBot App Checkout',
1825 1681 'post_name' => 'wpwbot-app-checkout',
1826 1682 'post_type' => 'page',
@@ -1830,16 +1686,15 @@
1830 1686 //save the id in the database
1831 1687 update_option('wp_chatbot_app_checkout', $app_checkout);
1832 1688 }
1833 1689 //App Order thank you page create
1834 - $existing_thankyou = new WP_Query( array( 'post_type' => 'page', 'name' => 'wpwbot-app-order-thankyou', 'post_status' => 'publish', 'posts_per_page' => 1 ) );
1835 - if ( ! $existing_thankyou->have_posts() ) {
1690 + if (get_page_by_title('wpwBot App Order Thank You') == NULL) {
1836 1691 //post status and options
1837 1692 $thankyou_page = array(
1838 1693 'comment_status' => 'closed',
1839 1694 'ping_status' => 'closed',
1840 1695 'post_author' => get_current_user_id(),
1841 - 'post_date' => gmdate('Y-m-d H:i:s'),
1696 + 'post_date' => date('Y-m-d H:i:s'),
1842 1697 'post_status' => 'publish',
1843 1698 'post_title' => 'wpwBot App Order Thank You',
1844 1699 'post_name' => 'wpwbot-app-order-thankyou',
1845 1700 'post_type' => 'page',
@@ -1850,9 +1705,9 @@
1850 1705 update_option('wp_chatbot_app_order_thankyou', $app_order_thankyou);
1851 1706 }
1852 1707 }
1853 1708 //Keep tracking from App by cookies
1854 - if ( isset( $_GET['from'] ) && sanitize_text_field( wp_unslash( $_GET['from'] ) ) === 'app' ) { // phpcs:ignore WordPress.Security.NonceVerification
1709 + if (isset($_GET['from']) && $_GET['from'] == 'app') {
1855 1710 if (!isset($_COOKIE['from_app'])) {
1856 1711 setcookie('from_app', 'yes', (time() + 3600), '/');
1857 1712 }
1858 1713 }
@@ -1866,9 +1721,9 @@
1866 1721 global $wp;
1867 1722 if (is_checkout() && !empty($wp->query_vars['order-received'])) {
1868 1723 $thanks_page_id = get_option('wp_chatbot_app_order_thankyou');
1869 1724 $thanks_parmanlink = esc_url(get_permalink($thanks_page_id));
1870 - wp_safe_redirect($thanks_parmanlink . '?order_id=' . $order_get_id);
1725 + wp_redirect($thanks_parmanlink . '?order_id=' . $order_get_id);
1871 1726 exit;
1872 1727 }
1873 1728 } else {
1874 1729 remove_action('wpcommerce_thankyou', 'qcld_wb_chatbot__redirect_after_purchase');
@@ -1876,12 +1731,9 @@
1876 1731 }
1877 1732 }
1878 1733
1879 1734 function qcld_choose_random($array){
1880 - if (is_array($array) && !empty($array)) {
1881 - return $array[array_rand($array)];
1882 - }
1883 - return $array;
1735 + return $array[array_rand($array)];
1884 1736 }
1885 1737
1886 1738 //User session count
1887 1739 add_action('wp_ajax_qcld_wb_chatbot_session_count', 'qcld_wb_chatbot_session_count');
@@ -1894,22 +1746,22 @@
1894 1746 $tableuser = $wpdb->prefix.'wpbot_sessions';
1895 1747 $response = array();
1896 1748
1897 1749
1898 - $session_exists = $wpdb->get_row($wpdb->prepare("select * from {$tableuser} where 1 and id = %d",1)); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, PluginCheck.Security.DirectDB.UnescapedDBParameter
1750 + $session_exists = $wpdb->get_row($wpdb->prepare("select * from $tableuser where 1 and id = %d",1)); //DB Call OK, No Caching OK
1899 1751
1900 1752 if(empty($session_exists)){
1901 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
1753 + $wpdb->insert(
1902 1754 $tableuser,
1903 1755 array(
1904 1756 'session' => 1,
1905 1757 )
1906 - );
1758 + ); //DB Call OK, No Caching OK
1907 1759 }else{
1908 1760
1909 1761 $session_id = $session_exists->id;
1910 1762
1911 - $wpdb->update( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1763 + $wpdb->update(
1912 1764 $tableuser,
1913 1765 array(
1914 1766 'session'=>($session_exists->session+1),
1915 1767 ),
@@ -1917,9 +1769,9 @@
1917 1769 array(
1918 1770 '%d',
1919 1771 ),
1920 1772 array('%d')
1921 - );
1773 + ); //DB Call OK, No Caching OK
1922 1774
1923 1775 }
1924 1776
1925 1777 wp_send_json($response);
@@ -1927,9 +1779,9 @@
1927 1779
1928 1780 /* WPBot Chat History Addon check */
1929 1781 function qcld_wpbot_is_active_chat_history(){
1930 1782
1931 - if(function_exists('qcwp_chat_session_menu_fnc') || function_exists('qcwp_chat_session_menu_fnc_free') || function_exists( 'qcpdcs_chat_session_menu_fnc' ) ){
1783 + if(function_exists('qcwp_chat_session_menu_fnc') || function_exists( 'qcpdcs_chat_session_menu_fnc' ) ){
1932 1784 return 1;
1933 1785 }else{
1934 1786 return 0;
1935 1787 }
@@ -1935,73 +1787,18 @@
1935 1787 }
1936 1788
1937 1789 }
1938 1790
1939 -/**
1940 - * Safely sanitize chatbot conversation input.
1941 - *
1942 - * SECURITY FIX (CVE WPBot Stored XSS ≤ 8.6.9):
1943 - * The previous order was: wp_kses() → html_entity_decode() → htmlspecialchars().
1944 - * An attacker could submit entity-encoded payloads (&lt;img onerror=...&gt;) that
1945 - * bypassed wp_kses (which saw inert text), were then decoded back into live markup
1946 - * by html_entity_decode(), and survived into storage and the admin UI.
1947 - *
1948 - * Correct order: html_entity_decode() FIRST → wp_kses() → htmlspecialchars().
1949 - * wp_kses() now sees the real decoded markup and strips forbidden tags/attributes.
1950 - *
1951 - * @param string $data Raw conversation string (already wp_unslash'd by caller).
1952 - * @return string Sanitized, entity-encoded string safe for DB storage.
1953 - */
1954 1791 function qcld_wpbot_input_validation( $data ) {
1955 - // 1. Decode any entity-encoded HTML so wp_kses sees the real markup.
1956 - $data = html_entity_decode( $data, ENT_QUOTES | ENT_HTML5, 'UTF-8' );
1957 - $data = trim( $data );
1958 - $data = stripslashes( $data );
1959 - // 2. Sanitize with a strict allowlist — NOW operating on decoded markup.
1960 - $data = wp_kses( $data, wpbot_get_safe_conversation_tags() );
1961 - // 3. Re-encode for safe DB storage; admin.js decodes for rendering.
1962 - $data = htmlspecialchars( $data, ENT_QUOTES | ENT_HTML5, 'UTF-8' );
1792 + $data = html_entity_decode($data);
1793 + $data = trim($data);
1794 + $data = stripslashes($data);
1795 + $data = htmlspecialchars($data);
1963 1796 return $data;
1964 1797 }
1965 -
1966 -/**
1967 - * Returns the strict HTML allowlist for chatbot conversation content.
1968 - *
1969 - * Critically: no event-handler attributes (onerror, onclick, onload, etc.) are
1970 - * allowed — wp_kses strips any attribute not explicitly listed here.
1971 - * 'img' is intentionally omitted; bot responses that include images should use
1972 - * safe URLs only and can be re-added with only 'src', 'alt', 'class' if needed.
1973 - *
1974 - * @return array<string, array<string, bool>>
1975 - */
1976 -function wpbot_get_safe_conversation_tags() {
1977 - return array(
1978 - 'ul' => array( 'class' => true ),
1979 - 'ol' => array( 'class' => true ),
1980 - 'li' => array( 'class' => true, 'id' => true ),
1981 - 'div' => array( 'class' => true, 'id' => true ),
1982 - 'span' => array( 'class' => true, 'id' => true ),
1983 - 'p' => array( 'class' => true ),
1984 - 'br' => array(),
1985 - 'strong' => array(),
1986 - 'em' => array(),
1987 - 'b' => array(),
1988 - 'i' => array(),
1989 - 'a' => array(
1990 - 'href' => true,
1991 - 'target' => true,
1992 - 'rel' => true,
1993 - 'class' => true,
1994 - ),
1995 - // 'img' intentionally excluded — prevents onerror/onload injection.
1996 - // Add back with only 'src','alt','class' if bot image responses are needed.
1997 - );
1998 -}
1999 1798 add_action('wp_ajax_qcld_small_talk_import', 'qcld_small_talk_import');
2000 1799 function qcld_small_talk_import(){
2001 - if ( ! current_user_can( 'manage_options' ) ) {
2002 - wp_die();
2003 - }
1800 +
2004 1801 global $wpdb;
2005 1802
2006 1803 $table = $wpdb->prefix.'wpbot_response';
2007 1804
@@ -2008,10 +1805,9 @@
2008 1805 $csvFile = file(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . 'small_talk.csv');
2009 1806
2010 1807 foreach ($csvFile as $line) {
2011 1808 $line = str_getcsv($line, ',', '"');
2012 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
2013 - $table, array(
1809 + $wpdb->insert($table, array(
2014 1810 'query' => $line[0],
2015 1811 'keyword' => $line[1],
2016 1812 'response' => $line[2],
2017 1813 'category'=> $line[3],
@@ -2016,17 +1812,16 @@
2016 1812 'response' => $line[2],
2017 1813 'category'=> $line[3],
2018 1814 'intent'=> '',
2019 1815 //'lang'=> 'en_US',
2020 - ));
1816 + )); //DB Call OK, No Caching OK
2021 1817 }
2022 1818
2023 1819 $table2 = $wpdb->prefix.'wpbot_response_category';
2024 1820
2025 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
2026 - $table2, array(
1821 + $wpdb->insert($table2, array(
2027 1822 'name' => 'smalltalk',
2028 - ));
1823 + )); //DB Call OK, No Caching OK
2029 1824
2030 1825 update_option( 'qcld_small_talk_imported', 'yes' );
2031 1826
2032 1827 }
@@ -2054,15 +1849,11 @@
2054 1849 function qcld_change_language_from_center() {
2055 1850 if ( ! current_user_can( 'manage_options' ) ) {
2056 1851 wp_send_json_error( array( 'message' => 'Unauthorized.' ) );
2057 1852 }
2058 - $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( wp_unslash( $_POST['nonce'] ) ) : '';
2059 - if ( ! wp_verify_nonce( $nonce, 'wp_chatbot' ) ) {
2060 - wp_send_json_error( array( 'message' => 'Invalid nonce.' ) );
2061 - }
2062 1853 $plugin_path = plugin_dir_path( __FILE__ );
2063 1854 include $plugin_path . 'includes/admin/settings-fields.php';
2064 - $json_file_path = $plugin_path . 'includes/language-center.json';
1855 + $json_file_path = $plugin_path . 'includes/language center.json'; // Adjust path as needed
2065 1856
2066 1857 $json_string = file_get_contents( $json_file_path );
2067 1858 if ( isset( $_POST['language'] ) ) {
2068 1859 $language = sanitize_text_field( wp_unslash( $_POST['language'] ) );
@@ -2073,8 +1864,5 @@
2073 1864 wp_send_json_error( array( 'message' => 'Language not specified.' ) );
2074 1865
2075 1866 }
2076 1867 }
2077 -}
2078 -
2079 -// AI Actions Chat Preview
2080 -
1868 +}