PluginProbe
WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services / 8.2.3
WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services v8.2.3
8.7.8 8.7.7 8.7.6 8.7.5 8.7.4 8.7.3 8.7.2 8.7.1 8.7.0 8.6.9 8.6.8 8.6.7 8.6.6 8.6.5 8.6.4 8.6.2 8.6.1 8.6.0 8.5.9 8.5.8 8.5.7 8.5.6 8.5.5 8.5.4 8.5.3 All 534 releases
← All changes | functions.php +30 -237 8.7.78.2.3 View file →
@@ -14,9 +14,9 @@
14 14 $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_agent_image');
15 15 } else {
16 16 $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . 'custom-agent.png';
17 17 }
18 - $hidden_field = '<a class="wp-chatbot qc_wpbot_chat_link" id="wp-chatbot-search-btn" data-search-type="product" data-search-term="" style="max-height: 50px; margin-left: 10px;padding: 0 !important;position: absolute;top: -9px;right: -60px;"><img src="'. esc_url($wp_chatbot_custom_agent_path) .'" alt=""></a>';
18 + $hidden_field = '<a class="wp-chatbot qc_wpbot_chat_link" id="wp-chatbot-search-btn" data-search-type="product" data-search-term="" style="max-height: 50px; margin-left: 10px;padding: 0 !important;position: absolute;top: -9px;right: -60px;"><img src="'. esc_attr($wp_chatbot_custom_agent_path) .'" alt=""></a>';
19 19 $block_content = str_replace( '</form>', $hidden_field . '</form>', $form );
20 20 return $block_content;
21 21 }
22 22 if(get_option('wpbot_enable_on_search') == 1 && (get_option('disable_floating_button') != '1') && get_option('disable_wp_chatbot') != 1 ){
@@ -33,9 +33,9 @@
33 33 $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_agent_image');
34 34 } else {
35 35 $wp_chatbot_custom_agent_path = QCLD_wpCHATBOT_IMG_URL . 'custom-agent.png';
36 36 }
37 - $hidden_field = '<button type="button" class="wp-chatbot qc_wpbot_chat_link" id="wp-chatbot-search-btn" data-search-type="product" data-search-term="" style="max-height: 50px; margin-left: 10px;padding: 0 !important"><img src="'. esc_url($wp_chatbot_custom_agent_path) .'" alt=""></button>';
37 + $hidden_field = '<button type="button" class="wp-chatbot qc_wpbot_chat_link" id="wp-chatbot-search-btn" data-search-type="product" data-search-term="" style="max-height: 50px; margin-left: 10px;padding: 0 !important"><img src="'. esc_attr($wp_chatbot_custom_agent_path) .'" alt=""></button>';
38 38 // Inject the hidden field before the closing </form> tag
39 39 $block_content = str_replace( '</div></form>', $hidden_field . '</div></form>', $block_content );
40 40 return $block_content;
41 41 }
@@ -58,62 +58,8 @@
58 58 });
59 59 </script>
60 60 <?php
61 61 }
62 -/**
63 - * Extract a YouTube video ID from common URL formats.
64 - *
65 - * @param string $url YouTube watch, embed, short, or youtu.be URL.
66 - * @return string Video ID or empty string.
67 - */
68 -if ( ! function_exists( 'qcld_wpbot_extract_youtube_id' ) ) {
69 - function qcld_wpbot_extract_youtube_id( $url ) {
70 - $url = trim( (string) $url );
71 - if ( $url === '' ) {
72 - return '';
73 - }
74 -
75 - if ( preg_match( '/(?:youtube\.com\/(?:embed\/|shorts\/|live\/|watch\?(?:.*&)?v=)|youtu\.be\/)([A-Za-z0-9_-]{11})/', $url, $matches ) ) {
76 - return $matches[1];
77 - }
78 -
79 - $path = (string) wp_parse_url( $url, PHP_URL_PATH );
80 - $base = basename( $path );
81 - if ( preg_match( '/^[A-Za-z0-9_-]{11}$/', $base ) ) {
82 - return $base;
83 - }
84 -
85 - return '';
86 - }
87 -}
88 -if ( ! function_exists( 'qcld_wpbot_youtube_icon_embed_src' ) ) {
89 - function qcld_wpbot_youtube_icon_embed_src( $url ) {
90 - $video_id = qcld_wpbot_extract_youtube_id( $url );
91 - if ( $video_id === '' ) {
92 - return '';
93 - }
94 -
95 - return add_query_arg(
96 - array(
97 - 'autoplay' => '1',
98 - 'mute' => '1',
99 - 'loop' => '1',
100 - 'playlist' => $video_id,
101 - 'controls' => '0',
102 - 'showinfo' => '0',
103 - 'rel' => '0',
104 - 'fs' => '0',
105 - 'iv_load_policy' => '3',
106 - 'cc_load_policy' => '0',
107 - 'disablekb' => '1',
108 - 'playsinline' => '1',
109 - 'modestbranding' => '1',
110 - 'color' => 'white',
111 - ),
112 - 'https://www.youtube.com/embed/' . rawurlencode( $video_id )
113 - );
114 - }
115 -}
116 62 function wp_chatbot_load_footer_html(){
117 63 if ( get_option('disable_wp_chatbot') != 1 && wp_chatbot_load_controlling() === true) {
118 64
119 65 ?>
@@ -119,9 +65,9 @@
119 65 ?>
120 66 <style>
121 67 <?php if(get_option('wp_chatbot_custom_css')!="") {
122 68
123 - echo wp_strip_all_tags( get_option('wp_chatbot_custom_css') );// phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
69 + echo wp_strip_all_tags( get_option('wp_chatbot_custom_css') );
124 70 }
125 71 ?>
126 72 </style>
127 73
@@ -133,27 +79,10 @@
133 79 }
134 80 ?>
135 81 <style>
136 82 .wp-chatbot-container {
137 - background-color: #eceef3 !important;
138 83 background-image: url(<?php echo esc_url($qcld_wb_chatbot_board_bg_path); ?>) !important;
139 - background-size: cover !important;
140 - background-position: center !important;
141 - background-repeat: no-repeat !important;
142 84 }
143 - .wp-chatbot-template-01 #wp-chatbot-board-container,
144 - .wp-chatbot-template-01 .wp-chatbot-board-container {
145 - background-color: #eceef3 !important;
146 - background-image: none !important;
147 - }
148 - .wp-chatbot-template-01 #wp-chatbot-board-container::before,
149 - .wp-chatbot-template-01 .wp-chatbot-board-container::before {
150 - background-color: #eceef3 !important;
151 - background-image: url(<?php echo esc_url($qcld_wb_chatbot_board_bg_path); ?>) !important;
152 - background-size: cover !important;
153 - background-position: center !important;
154 - background-repeat: no-repeat !important;
155 - }
156 85 </style>
157 86 <?php }
158 87 $wp_chatbot_enable_rtl = "";
159 88 if (get_option('enable_wp_chatbot_rtl') == '1') {
@@ -226,9 +155,9 @@
226 155 }
227 156 ?>
228 157 <div class="wp-chatbot-notification-agent-profile">
229 158 <div class="wp-chatbot-notification-widget-avatar" ><img
230 - src="<?php echo esc_url($wp_chatbot_custom_agent_path); ?>" alt=""></div>
159 + src="<?php echo esc_attr($wp_chatbot_custom_agent_path); ?>" alt=""></div>
231 160 <div class="wp-chatbot-notification-welcome"><?php echo wp_kses_post(wpb_randmom_message_handle(maybe_unserialize(get_option('qlcd_wp_chatbot_welcome')))) . ' <strong>' . esc_html(get_option('qlcd_wp_chatbot_host')) . '</strong>'; ?></div>
232 161 </div>
233 162 <?php
234 163 //update_option('qlcd_wp_chatbot_notifications','Welcome to WpBot');
@@ -251,72 +180,14 @@
251 180 $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . get_option('wp_chatbot_icon');
252 181 } else {
253 182 $wp_chatbot_custom_icon_path = QCLD_wpCHATBOT_IMG_URL . 'custom.png';
254 183 }
255 - $_wpbot_icon_video = get_option('wp_chatbot_icon_video', '');
256 - $_wpbot_video_is_youtube = ( strpos( $_wpbot_icon_video, 'youtube.com' ) !== false || strpos( $_wpbot_icon_video, 'youtu.be' ) !== false );
257 - $_wpbot_youtube_embed_src = $_wpbot_video_is_youtube ? qcld_wpbot_youtube_icon_embed_src( $_wpbot_icon_video ) : '';
258 - $_wpbot_video_delay_ms = absint( get_option( 'wp_chatbot_icon_video_delay', 0 ) ) * 1000;
259 -
260 - $wp_chatbot_ball_is_youtube = ($_wpbot_icon_video !== '' && (strpos($_wpbot_icon_video, 'youtube.com') !== false || strpos($_wpbot_icon_video, 'youtu.be') !== false));
261 - $wp_chatbot_ball_is_video = ($_wpbot_icon_video !== '' && !$wp_chatbot_ball_is_youtube);
262 - $wp_chatbot_ball_has_video = ($wp_chatbot_ball_is_youtube || $wp_chatbot_ball_is_video);
263 184 ?>
264 185 <img src="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>"
265 - alt="wpChatIcon" qcld_agent="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>"
266 - id="wp-chatbot-ball-icon-img"
267 - <?php if ($wp_chatbot_ball_has_video) { echo 'style="display:none;"'; } ?> >
268 - <?php if ( $_wpbot_icon_video !== '' ) : ?>
269 - <?php if ( $_wpbot_video_is_youtube && $_wpbot_youtube_embed_src !== '' ) : ?>
270 - <iframe class="wpbot-icon-video" src="<?php echo $_wpbot_video_delay_ms > 0 ? 'about:blank' : esc_url( $_wpbot_youtube_embed_src ); ?>" data-wpbot-yt-src="<?php echo esc_url( $_wpbot_youtube_embed_src ); ?>" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture"></iframe>
271 - <?php elseif ( ! $_wpbot_video_is_youtube ) : ?>
272 - <video class="wpbot-icon-video" src="<?php echo esc_url( $_wpbot_icon_video ); ?>" autoplay muted loop playsinline preload="auto"></video>
273 - <?php endif; ?>
274 - <?php endif; ?>
186 + alt="wpChatIcon" qcld_agent="<?php echo esc_url($wp_chatbot_custom_icon_path); ?>" >
187 +
275 188 </div>
276 -
277 189 </div>
278 - <?php
279 - if ( $_wpbot_icon_video !== '' ) :
280 - ?>
281 - <script>
282 - (function(){
283 - var wpbotDelay = <?php echo (int) $_wpbot_video_delay_ms; ?>;
284 - function wpbotForcePlay(){
285 - var v = document.querySelector('#wp-chatbot-ball video.wpbot-icon-video');
286 - if( v ){
287 - v.muted = true;
288 - v.volume = 0;
289 - v.loop = true;
290 - var tries = 0, maxTries = 30;
291 - var timer = setInterval(function(){
292 - tries++;
293 - v.play().then(function(){ clearInterval(timer); }).catch(function(){});
294 - if( tries >= maxTries ) clearInterval(timer);
295 - }, 300);
296 - }
297 - var yt = document.querySelector('#wp-chatbot-ball iframe.wpbot-icon-video');
298 - if( yt ){
299 - var ytSrc = yt.getAttribute('data-wpbot-yt-src');
300 - if( ytSrc && ( !yt.getAttribute('src') || yt.getAttribute('src') === 'about:blank' || yt.getAttribute('src').indexOf('autoplay=1') === -1 ) ){
301 - yt.setAttribute('src', ytSrc);
302 - }
303 - }
304 - }
305 - function wpbotDelayedPlay(){
306 - setTimeout(wpbotForcePlay, wpbotDelay);
307 - }
308 - if( document.readyState === 'loading' ){
309 - document.addEventListener('DOMContentLoaded', wpbotDelayedPlay);
310 - } else {
311 - wpbotDelayedPlay();
312 - }
313 - window.addEventListener('load', function(){
314 - setTimeout(wpbotForcePlay, wpbotDelay);
315 - });
316 - })();
317 - </script>
318 - <?php endif; ?>
319 190 <?php
320 191 $fb_app_id = get_option('qlcd_wp_chatbot_fb_app_id');
321 192 $fb_page_id = get_option('qlcd_wp_chatbot_fb_page_id');
322 193 $fb_mgs_color = get_option('qlcd_wp_chatbot_fb_color') != '' ? get_option('qlcd_wp_chatbot_fb_color') : '#0084ff';
@@ -467,15 +338,8 @@
467 338 */
468 339 add_action('wp_ajax_qcld_wb_chatbot_keyword', 'qcld_wb_chatbot_keyword');
469 340 add_action('wp_ajax_nopriv_qcld_wb_chatbot_keyword', 'qcld_wb_chatbot_keyword');
470 341 function qcld_wb_chatbot_keyword(){
471 - // Verify nonce for security
472 - $nonce = isset($_POST['security']) ? sanitize_text_field(wp_unslash($_POST['security'])) : (isset($_POST['nonce']) ? sanitize_text_field(wp_unslash($_POST['nonce'])) : '');
473 - if ( ! wp_verify_nonce( $nonce, 'wp_chatbot' ) && ! wp_verify_nonce( $nonce, 'qcsecretbotnonceval123qc' ) ) {
474 - wp_send_json_error( array( 'status' => 'fail', 'message' => 'Security check failed.' ) );
475 - wp_die();
476 - }
477 -
478 342 $keyword = sanitize_text_field(wp_unslash($_POST['keyword']));
479 343 $product_per_page = get_option('qlcd_wp_chatbot_ppp') != '' ? get_option('qlcd_wp_chatbot_ppp') : 10;
480 344 if (get_option('qlcd_wp_chatbot_search_option') == 'standard') {
481 345 $product_orderby = sanitize_text_field(get_option('qlcd_wp_chatbot_product_orderby') != '' ? get_option('qlcd_wp_chatbot_product_orderby') : 'title');
@@ -522,9 +386,9 @@
522 386 endwhile;
523 387 wp_reset_postdata();
524 388 $html .= '</ul>';
525 389 if ($total_product_num > $product_per_page && $product_per_page > 0 ) {
526 - $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . esc_attr($keyword) . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
390 + $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . $keyword . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
527 391 }
528 392 }
529 393 $html .= '</div>';
530 394 } else if (get_option('qlcd_wp_chatbot_search_option') == 'advanced') {
@@ -552,9 +416,9 @@
552 416 }
553 417 }
554 418 $html .= '</ul>';
555 419 if ($total_product_num > $product_per_page && $product_per_page > 0) {
556 - $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . esc_attr($more_product_ids) . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
420 + $html .= '<p style="text-align: center"><button type="button" id="wp-chatbot-loadmore" data-offset="' . $product_per_page . '" data-search-type="product" data-search-term="' . $more_product_ids . '" >' . wp_kses_post(wpb_randmom_message_handle(unserialize(get_option('qlcd_wp_chatbot_load_more')))) . ' <span id="wp-chatbot-loadmore-loader"></span></button> </p>';
557 421 }
558 422 }
559 423 $html .= '</div>';
560 424 }
@@ -1121,12 +985,9 @@
1121 985 //Support part
1122 986 add_action('wp_ajax_qcld_wb_chatbot_support_email', 'qcld_wb_chatbot_support_email');
1123 987 add_action('wp_ajax_nopriv_qcld_wb_chatbot_support_email', 'qcld_wb_chatbot_support_email');
1124 988 function qcld_wb_chatbot_support_email(){
1125 - $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( wp_unslash( $_POST['nonce'] ) ) : '';
1126 - if ( ! wp_verify_nonce( $nonce, 'qcsecretbotnonceval123qc' ) ) {
1127 - wp_send_json_error( array( 'error' => esc_html__( 'Error: Invalid nonce verification.', 'chatbot' ) ) );
1128 - }
989 + check_ajax_referer('qcsecretbotnonceval123qc', 'nonce');
1129 990 $name = trim(sanitize_text_field(wp_unslash($_POST['name'])));
1130 991 $email = sanitize_email(wp_unslash($_POST['email']));
1131 992 $message = sanitize_text_field(wp_unslash($_POST['message']));
1132 993 $subject = sanitize_text_field(get_option('qlcd_wp_chatbot_email_sub') != '' ? get_option('qlcd_wp_chatbot_email_sub') : 'Support Email from wpWBot by Client');
@@ -1143,8 +1004,9 @@
1143 1004 $fromEmail = get_option('qlcd_wp_chatbot_from_email');
1144 1005 }else{
1145 1006 $fromEmail = "wordpress@" . $domain;
1146 1007 }
1008 +
1147 1009 //Starting messaging and status.
1148 1010 $response['status'] = 'fail';
1149 1011 $response['message'] = str_replace('\\', '',wp_kses_post(get_option('qlcd_wp_chatbot_email_fail')));
1150 1012 if (filter_var($email, FILTER_VALIDATE_EMAIL) === false) {
@@ -1402,9 +1264,9 @@
1402 1264 $html .= get_the_post_thumbnail(get_the_ID(), 'shop_catalog') . '
1403 1265 <div class="wp-chatbot-product-summary">
1404 1266 <div class="wp-chatbot-product-table">
1405 1267 <div class="wp-chatbot-product-table-cell">
1406 - <h3 class="wp-chatbot-product-title">' . esc_html($product->post->post_title) . '</h3>
1268 + <h3 class="wp-chatbot-product-title">' . $product->post->post_title . '</h3>
1407 1269 <div class="price">' . $product->get_price_html() . '</div>';
1408 1270 $html .= ' </div>
1409 1271 </div>
1410 1272 </div></a>
@@ -1473,9 +1335,9 @@
1473 1335 $html .= get_the_post_thumbnail(get_the_ID(), 'shop_catalog') . '
1474 1336 <div class="wp-chatbot-product-summary">
1475 1337 <div class="wp-chatbot-product-table">
1476 1338 <div class="wp-chatbot-product-table-cell">
1477 - <h3 class="wp-chatbot-product-title">' . esc_html($product->post->post_title) . '</h3>
1339 + <h3 class="wp-chatbot-product-title">' . $product->post->post_title . '</h3>
1478 1340 <div class="price">' . $product->get_price_html() . '</div>';
1479 1341 $html .= ' </div>
1480 1342 </div>
1481 1343 </div></a>
@@ -1649,9 +1511,8 @@
1649 1511 //Updating the cart items.
1650 1512 add_action('wp_ajax_qcld_wb_chatbot_update_cart_item_number', 'qcld_wb_chatbot_update_cart_item_number');
1651 1513 add_action('wp_ajax_nopriv_qcld_wb_chatbot_update_cart_item_number', 'qcld_wb_chatbot_update_cart_item_number');
1652 1514 function qcld_wb_chatbot_update_cart_item_number(){
1653 - check_ajax_referer( 'wp_chatbot', 'nonce' );
1654 1515 //getting cart items n
1655 1516 $cart_item_key = sanitize_text_field(wp_unslash($_POST['cart_item_key']));
1656 1517 $qnty = sanitize_text_field(wp_unslash($_POST['qnty']));
1657 1518 global $wpcommerce;
@@ -1661,9 +1522,8 @@
1661 1522 //Show item after removing from cart page.
1662 1523 add_action('wp_ajax_qcld_wb_chatbot_cart_item_remove', 'qcld_wb_chatbot_cart_item_remove');
1663 1524 add_action('wp_ajax_nopriv_qcld_wb_chatbot_cart_item_remove', 'qcld_wb_chatbot_cart_item_remove');
1664 1525 function qcld_wb_chatbot_cart_item_remove(){
1665 - check_ajax_referer( 'wp_chatbot', 'nonce' );
1666 1526 //getting cart items n
1667 1527 $cart_item_key = sanitize_text_field(wp_unslash($_POST['cart_item']));
1668 1528 global $wpcommerce;
1669 1529 $result = $wpcommerce->cart->remove_cart_item($cart_item_key);
@@ -1721,9 +1581,9 @@
1721 1581
1722 1582 if(class_exists('Qcformbuilder_Forms_Admin')){
1723 1583
1724 1584
1725 - $results = $wpdb->get_results($wpdb->prepare("SELECT * FROM ". $wpdb->prefix."wfb_forms WHERE type= %s",'primary')); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1585 + $results = $wpdb->get_results($wpdb->prepare("SELECT * FROM ". $wpdb->prefix."wfb_forms WHERE type= %s",'primary')); //DB Call OK, No Caching OK
1726 1586
1727 1587 if(!empty($results)){
1728 1588
1729 1589 foreach($results as $result){
@@ -1876,12 +1736,9 @@
1876 1736 }
1877 1737 }
1878 1738
1879 1739 function qcld_choose_random($array){
1880 - if (is_array($array) && !empty($array)) {
1881 - return $array[array_rand($array)];
1882 - }
1883 - return $array;
1740 + return $array[array_rand($array)];
1884 1741 }
1885 1742
1886 1743 //User session count
1887 1744 add_action('wp_ajax_qcld_wb_chatbot_session_count', 'qcld_wb_chatbot_session_count');
@@ -1894,22 +1751,22 @@
1894 1751 $tableuser = $wpdb->prefix.'wpbot_sessions';
1895 1752 $response = array();
1896 1753
1897 1754
1898 - $session_exists = $wpdb->get_row($wpdb->prepare("select * from {$tableuser} where 1 and id = %d",1)); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, PluginCheck.Security.DirectDB.UnescapedDBParameter
1755 + $session_exists = $wpdb->get_row($wpdb->prepare("select * from $tableuser where 1 and id = %d",1)); //DB Call OK, No Caching OK
1899 1756
1900 1757 if(empty($session_exists)){
1901 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
1758 + $wpdb->insert(
1902 1759 $tableuser,
1903 1760 array(
1904 1761 'session' => 1,
1905 1762 )
1906 - );
1763 + ); //DB Call OK, No Caching OK
1907 1764 }else{
1908 1765
1909 1766 $session_id = $session_exists->id;
1910 1767
1911 - $wpdb->update( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1768 + $wpdb->update(
1912 1769 $tableuser,
1913 1770 array(
1914 1771 'session'=>($session_exists->session+1),
1915 1772 ),
@@ -1917,9 +1774,9 @@
1917 1774 array(
1918 1775 '%d',
1919 1776 ),
1920 1777 array('%d')
1921 - );
1778 + ); //DB Call OK, No Caching OK
1922 1779
1923 1780 }
1924 1781
1925 1782 wp_send_json($response);
@@ -1927,9 +1784,9 @@
1927 1784
1928 1785 /* WPBot Chat History Addon check */
1929 1786 function qcld_wpbot_is_active_chat_history(){
1930 1787
1931 - if(function_exists('qcwp_chat_session_menu_fnc') || function_exists('qcwp_chat_session_menu_fnc_free') || function_exists( 'qcpdcs_chat_session_menu_fnc' ) ){
1788 + if(function_exists('qcwp_chat_session_menu_fnc') || function_exists( 'qcpdcs_chat_session_menu_fnc' ) ){
1932 1789 return 1;
1933 1790 }else{
1934 1791 return 0;
1935 1792 }
@@ -1935,73 +1792,18 @@
1935 1792 }
1936 1793
1937 1794 }
1938 1795
1939 -/**
1940 - * Safely sanitize chatbot conversation input.
1941 - *
1942 - * SECURITY FIX (CVE WPBot Stored XSS ≤ 8.6.9):
1943 - * The previous order was: wp_kses() → html_entity_decode() → htmlspecialchars().
1944 - * An attacker could submit entity-encoded payloads (&lt;img onerror=...&gt;) that
1945 - * bypassed wp_kses (which saw inert text), were then decoded back into live markup
1946 - * by html_entity_decode(), and survived into storage and the admin UI.
1947 - *
1948 - * Correct order: html_entity_decode() FIRST → wp_kses() → htmlspecialchars().
1949 - * wp_kses() now sees the real decoded markup and strips forbidden tags/attributes.
1950 - *
1951 - * @param string $data Raw conversation string (already wp_unslash'd by caller).
1952 - * @return string Sanitized, entity-encoded string safe for DB storage.
1953 - */
1954 1796 function qcld_wpbot_input_validation( $data ) {
1955 - // 1. Decode any entity-encoded HTML so wp_kses sees the real markup.
1956 - $data = html_entity_decode( $data, ENT_QUOTES | ENT_HTML5, 'UTF-8' );
1957 - $data = trim( $data );
1958 - $data = stripslashes( $data );
1959 - // 2. Sanitize with a strict allowlist — NOW operating on decoded markup.
1960 - $data = wp_kses( $data, wpbot_get_safe_conversation_tags() );
1961 - // 3. Re-encode for safe DB storage; admin.js decodes for rendering.
1962 - $data = htmlspecialchars( $data, ENT_QUOTES | ENT_HTML5, 'UTF-8' );
1797 + $data = html_entity_decode($data);
1798 + $data = trim($data);
1799 + $data = stripslashes($data);
1800 + $data = htmlspecialchars($data);
1963 1801 return $data;
1964 1802 }
1965 -
1966 -/**
1967 - * Returns the strict HTML allowlist for chatbot conversation content.
1968 - *
1969 - * Critically: no event-handler attributes (onerror, onclick, onload, etc.) are
1970 - * allowed — wp_kses strips any attribute not explicitly listed here.
1971 - * 'img' is intentionally omitted; bot responses that include images should use
1972 - * safe URLs only and can be re-added with only 'src', 'alt', 'class' if needed.
1973 - *
1974 - * @return array<string, array<string, bool>>
1975 - */
1976 -function wpbot_get_safe_conversation_tags() {
1977 - return array(
1978 - 'ul' => array( 'class' => true ),
1979 - 'ol' => array( 'class' => true ),
1980 - 'li' => array( 'class' => true, 'id' => true ),
1981 - 'div' => array( 'class' => true, 'id' => true ),
1982 - 'span' => array( 'class' => true, 'id' => true ),
1983 - 'p' => array( 'class' => true ),
1984 - 'br' => array(),
1985 - 'strong' => array(),
1986 - 'em' => array(),
1987 - 'b' => array(),
1988 - 'i' => array(),
1989 - 'a' => array(
1990 - 'href' => true,
1991 - 'target' => true,
1992 - 'rel' => true,
1993 - 'class' => true,
1994 - ),
1995 - // 'img' intentionally excluded — prevents onerror/onload injection.
1996 - // Add back with only 'src','alt','class' if bot image responses are needed.
1997 - );
1998 -}
1999 1803 add_action('wp_ajax_qcld_small_talk_import', 'qcld_small_talk_import');
2000 1804 function qcld_small_talk_import(){
2001 - if ( ! current_user_can( 'manage_options' ) ) {
2002 - wp_die();
2003 - }
1805 +
2004 1806 global $wpdb;
2005 1807
2006 1808 $table = $wpdb->prefix.'wpbot_response';
2007 1809
@@ -2008,10 +1810,9 @@
2008 1810 $csvFile = file(QCLD_wpCHATBOT_PLUGIN_DIR_PATH . 'small_talk.csv');
2009 1811
2010 1812 foreach ($csvFile as $line) {
2011 1813 $line = str_getcsv($line, ',', '"');
2012 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
2013 - $table, array(
1814 + $wpdb->insert($table, array(
2014 1815 'query' => $line[0],
2015 1816 'keyword' => $line[1],
2016 1817 'response' => $line[2],
2017 1818 'category'=> $line[3],
@@ -2016,17 +1817,16 @@
2016 1817 'response' => $line[2],
2017 1818 'category'=> $line[3],
2018 1819 'intent'=> '',
2019 1820 //'lang'=> 'en_US',
2020 - ));
1821 + )); //DB Call OK, No Caching OK
2021 1822 }
2022 1823
2023 1824 $table2 = $wpdb->prefix.'wpbot_response_category';
2024 1825
2025 - $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
2026 - $table2, array(
1826 + $wpdb->insert($table2, array(
2027 1827 'name' => 'smalltalk',
2028 - ));
1828 + )); //DB Call OK, No Caching OK
2029 1829
2030 1830 update_option( 'qcld_small_talk_imported', 'yes' );
2031 1831
2032 1832 }
@@ -2054,12 +1854,8 @@
2054 1854 function qcld_change_language_from_center() {
2055 1855 if ( ! current_user_can( 'manage_options' ) ) {
2056 1856 wp_send_json_error( array( 'message' => 'Unauthorized.' ) );
2057 1857 }
2058 - $nonce = isset( $_POST['nonce'] ) ? sanitize_text_field( wp_unslash( $_POST['nonce'] ) ) : '';
2059 - if ( ! wp_verify_nonce( $nonce, 'wp_chatbot' ) ) {
2060 - wp_send_json_error( array( 'message' => 'Invalid nonce.' ) );
2061 - }
2062 1858 $plugin_path = plugin_dir_path( __FILE__ );
2063 1859 include $plugin_path . 'includes/admin/settings-fields.php';
2064 1860 $json_file_path = $plugin_path . 'includes/language-center.json';
2065 1861
@@ -2073,8 +1869,5 @@
2073 1869 wp_send_json_error( array( 'message' => 'Language not specified.' ) );
2074 1870
2075 1871 }
2076 1872 }
2077 -}
2078 -
2079 -// AI Actions Chat Preview
2080 -
1873 +}