PluginProbe
WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services / 8.8.1
WPBot – AI ChatBot for Live Support, Lead Generation, WordPress Automation, AI Services v8.8.1
8.8.1 8.8.0 8.7.9 8.7.8 8.7.7 8.7.6 8.7.5 8.7.4 8.7.3 8.7.2 8.7.1 8.7.0 8.6.9 8.6.8 8.6.7 8.6.6 8.6.5 8.6.4 8.6.2 8.6.1 8.6.0 8.5.9 8.5.8 8.5.7 8.5.6 All 537 releases
← All changes | qcld-wpwbot-search.php +46 -40 8.6.6 → 8.8.1 View file →
@@ -148,11 +148,11 @@
148 148 $where_clause = " AND (post_title LIKE %s)";
149 149 $sql_params[] = '%' . $wpdb->esc_like($keyword) . '%';
150 150 }
151 151
152 - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.InterpolatedNotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
152 + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
153 153 $results = $wpdb->get_results( $wpdb->prepare(
154 - "SELECT * FROM " . $wpdb->prefix . "posts WHERE post_status = %s " . $where_clause . " ORDER BY ID DESC LIMIT %d",
154 + "SELECT * FROM " . $wpdb->prefix . "posts WHERE post_status = %s " . $where_clause . " ORDER BY ID DESC LIMIT %d", // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
155 155 array_merge(['publish'], $sql_params, [$limit])
156 156 ) );
157 157 }
158 158
@@ -460,9 +460,9 @@
460 460 ));
461 461 }
462 462 } else {
463 463 if ( $orderby != 'none' && $orderby != 'rand' ) {
464 - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.InterpolatedNotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
464 + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
465 465 $results = $wpdb->get_results( $wpdb->prepare(
466 466 "SELECT * FROM " . $wpdb->prefix . "posts
467 467 WHERE post_type = %s
468 468 AND post_status = %s
@@ -467,9 +467,9 @@
467 467 WHERE post_type = %s
468 468 AND post_status = %s
469 469 AND (post_title REGEXP %s OR post_content REGEXP %s)
470 470 ORDER BY " . $orderby . " " . $order . "
471 - LIMIT %d, %d",
471 + LIMIT %d, %d", // phpcs:ignore WordPress.DB.PreparedSQL.NotPrepared
472 472 $post_type,
473 473 'publish',
474 474 '[[:<:]]' . $searchkeyword . '[[:>:]]',
475 475 '[[:<:]]' . $searchkeyword . '[[:>:]]',
@@ -636,11 +636,12 @@
636 636 global $wpdb;
637 637
638 638 $keyword = isset( $_POST['keyword'] ) ? sanitize_text_field(wp_unslash($_POST['keyword'])) : '';
639 639
640 - $table = $wpdb->prefix.'wpbot_response';
640 + $table = $wpdb->prefix . 'wpbot_response';
641 + $table_sql = '`' . esc_sql( $table ) . '`';
641 642
642 - $result = $wpdb->get_row( $wpdb->prepare("SELECT `response` FROM %i WHERE 1 and `intent` = %s", $table, $keyword) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
643 + $result = $wpdb->get_row( $wpdb->prepare( "SELECT `response` FROM {$table_sql} WHERE 1 AND `intent` = %s", $keyword ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
643 644
644 645 $response = array('status'=>'fail');
645 646
646 647 if(!empty($result)){
@@ -657,9 +658,10 @@
657 658 }
658 659 function qcld_wb_chatbot_email_subscription() {
659 660
660 661 global $wpdb;
661 - $table = $wpdb->prefix . 'wpbot_subscription';
662 + $table = $wpdb->prefix . 'wpbot_subscription';
663 + $table_sql = '`' . esc_sql( $table ) . '`';
662 664
663 665 $name = sanitize_text_field( $_POST['name'] );// phpcs:ignore WordPress.Security.NonceVerification.Missing
664 666 $email = sanitize_email( $_POST['email'] );// phpcs:ignore WordPress.Security.NonceVerification.Missing
665 667 $url = esc_url_raw( $_POST['url'] );// phpcs:ignore WordPress.Security.NonceVerification.Missing
@@ -669,9 +671,9 @@
669 671
670 672 $phone = sanitize_text_field( $_POST['phone'] );// phpcs:ignore WordPress.Security.NonceVerification.Missing
671 673 if ( $email != '' ) {
672 674
673 - $email_exists = $wpdb->get_row( $wpdb->prepare( "select * from %i where 1 and email = %s", $table, $email ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, PluginCheck.Security.DirectDB.UnescapedDBParameter
675 + $email_exists = $wpdb->get_row( $wpdb->prepare( "SELECT * FROM {$table_sql} WHERE 1 AND email = %s", $email ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
674 676 if ( ! empty( $email_exists ) ) {
675 677 $wpdb->update( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
676 678 $table,
677 679 array(
@@ -717,9 +719,9 @@
717 719
718 720 $response = array();
719 721 $response['status'] = 'fail';
720 722
721 - $email_exists = $wpdb->get_row( $wpdb->prepare( "select * from %i where 1 and email = %s", $table, $email ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, PluginCheck.Security.DirectDB.UnescapedDBParameter
723 + $email_exists = $wpdb->get_row( $wpdb->prepare( "SELECT * FROM {$table_sql} WHERE 1 AND email = %s", $email ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
722 724 if ( empty( $email_exists ) ) {
723 725
724 726 $wpdb->insert( // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery
725 727 $table,
@@ -784,10 +786,10 @@
784 786 }
785 787
786 788 // Extract Domain
787 789 $url = get_site_url();
788 - $url = parse_url( $url );
789 - $domain = $url['host'];
790 + $url = wp_parse_url( $url );
791 + $domain = isset( $url['host'] ) ? $url['host'] : '';
790 792 $toEmail = $email;
791 793 $fromEmail = 'wordpress@' . $domain;
792 794 $fromname = ( get_option( 'qlcd_wp_chatbot_from_name' ) ? get_option( 'qlcd_wp_chatbot_from_name' ) : 'WordPress' );
793 795
@@ -807,9 +809,9 @@
807 809 $offertexts = $offertexts[ get_wpbot_locale() ];
808 810 }
809 811 // build email body.
810 812 $bodyContent = '';
811 - $bodyContent .= '<p><strong>' . esc_html__( 'Offer Details', 'wpchatbot' ) . ':</strong></p><hr>';
813 + $bodyContent .= '<p><strong>' . esc_html__( 'Offer Details', 'chatbot' ) . ':</strong></p><hr>';
812 814 if ( is_array( $offertexts ) && ! empty( $offertexts ) ) {
813 815 $bodyContent .= '<p>' . str_replace( '%%username%%', $name, $offertexts[ array_rand( $offertexts ) ] ) . '</p>';
814 816 } elseif ( is_string( $offertexts ) && ! empty( $offertexts ) ) {
815 817 $bodyContent .= '<p>' . str_replace( '%%username%%', $name, $offertexts ) . '</p>';
@@ -815,9 +817,9 @@
815 817 $bodyContent .= '<p>' . str_replace( '%%username%%', $name, $offertexts ) . '</p>';
816 818 } else {
817 819 $bodyContent .= '<p></p>';
818 820 }
819 - $bodyContent .= '<p>' . esc_html__( 'Mail Generated on', 'wpchatbot' ) . ': ' . current_time( 'F j, Y, g:i a' ) . '</p>';
821 + $bodyContent .= '<p>' . esc_html__( 'Mail Generated on', 'chatbot' ) . ': ' . current_time( 'F j, Y, g:i a' ) . '</p>';
820 822 $to = $toEmail;
821 823 $body = $bodyContent;
822 824
823 825 $headers = array();
@@ -844,8 +846,9 @@
844 846 if ( count( $array ) == 0 ) {
845 847 return null;
846 848 }
847 849 ob_start();
850 + // phpcs:disable WordPress.WP.AlternativeFunctions.file_system_operations_fopen, WordPress.WP.AlternativeFunctions.file_system_operations_fclose -- php://output memory stream for CSV export.
848 851 $df = fopen( 'php://output', 'w' );
849 852 fputcsv( $df, array( 'Name', 'Email' ), ',', '"', '\\' );
850 853 foreach ( $array as $row ) {
851 854 fputcsv( $df, $row, ',', '"', '\\' );
@@ -850,8 +853,9 @@
850 853 foreach ( $array as $row ) {
851 854 fputcsv( $df, $row, ',', '"', '\\' );
852 855 }
853 856 fclose( $df );
857 + // phpcs:enable WordPress.WP.AlternativeFunctions.file_system_operations_fopen, WordPress.WP.AlternativeFunctions.file_system_operations_fclose
854 858 return ob_get_clean();
855 859 }
856 860 }
857 861
@@ -856,15 +860,16 @@
856 860 }
857 861
858 862 function qcld_wpb_export_email_csv() {
859 863 global $wpdb;
860 - $table = $wpdb->prefix . 'wpbot_subscription';
864 + $table = $wpdb->prefix . 'wpbot_subscription';
865 + $table_sql = '`' . esc_sql( $table ) . '`';
861 866
862 867 if ( ! current_user_can( 'manage_options' ) ) {
863 868 return;
864 869 }
865 870
866 - $emails = $wpdb->get_results( $wpdb->prepare( "select * from %i WHERE %d", $table, 1 ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, PluginCheck.Security.DirectDB.UnescapedDBParameter
871 + $emails = $wpdb->get_results( "SELECT * FROM {$table_sql}" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
867 872 $childArray = array();
868 873 foreach ( $emails as $email ) {
869 874 $innerArray = array();
870 875 $innerArray[0] = $email->name;
@@ -897,11 +902,12 @@
897 902
898 903 if( !function_exists( 'wpbo_search_response_catlist' )){
899 904 function wpbo_search_response_catlist(){
900 905 global $wpdb;
901 - $table = $wpdb->prefix.'wpbot_response_category';
902 - $status = array('status'=>'fail');
903 - $results = $wpdb->get_results($wpdb->prepare("SELECT * FROM %i", $table)); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
906 + $table = $wpdb->prefix . 'wpbot_response_category';
907 + $table_sql = '`' . esc_sql( $table ) . '`';
908 + $status = array( 'status' => 'fail' );
909 + $results = $wpdb->get_results( "SELECT * FROM {$table_sql}" ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
904 910 $response_result = array();
905 911
906 912 if(!empty($results)){
907 913 foreach($results as $result){
@@ -931,19 +937,19 @@
931 937
932 938 function qcld_wpbo_search_response(){
933 939
934 940 global $wpdb;
935 - $keyword = isset( $_POST['keyword'] ) ? (sanitize_text_field(wp_unslash($_POST['keyword']))) : '';
936 - $strid = isset( $_POST['strid'] ) ? (sanitize_text_field(wp_unslash($_POST['strid']))) : '';
937 - $table = $wpdb->prefix.'wpbot_response';
938 -
941 + $keyword = isset( $_POST['keyword'] ) ? ( sanitize_text_field( wp_unslash( $_POST['keyword'] ) ) ) : '';
942 + $strid = isset( $_POST['strid'] ) ? ( sanitize_text_field( wp_unslash( $_POST['strid'] ) ) ) : '';
943 + $table = $wpdb->prefix . 'wpbot_response';
944 + $table_sql = '`' . esc_sql( $table ) . '`';
939 945
940 946 $response_result = array();
941 947
942 - $status = array('status'=>'fail', 'multiple'=>false);
943 - $field = "ID";
944 - if(($strid != '') && empty($response_result)){
945 - $results = $wpdb->get_results($wpdb->prepare("SELECT * FROM %i WHERE %i = %d",$table,$field,$strid)); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
948 + $status = array( 'status' => 'fail', 'multiple' => false );
949 + $field = 'ID';
950 + if ( ( $strid != '' ) && empty( $response_result ) ) {
951 + $results = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM {$table_sql} WHERE `ID` = %d", $strid ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
946 952 if(!empty($results)){
947 953 foreach($results as $result){
948 954
949 955 $response_result[] = array('id'=>$result->id,'query'=>$result->query, 'response'=>$result->response, 'score'=>1);
@@ -950,10 +956,10 @@
950 956
951 957 }
952 958 }
953 959 }
954 - $field = "query";
955 - $results = $wpdb->get_results( $wpdb->prepare("SELECT `id`, `query`, `response` FROM %i WHERE 1 and %i = %s", $table, $field,$keyword) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
960 + $field = 'query';
961 + $results = $wpdb->get_results( $wpdb->prepare( "SELECT `id`, `query`, `response` FROM {$table_sql} WHERE 1 AND `query` = %s", $keyword ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
956 962
957 963
958 964 if(!empty($results)){
959 965 foreach($results as $result){
@@ -962,11 +968,11 @@
962 968
963 969 }
964 970 }
965 971
966 - $field = "category";
967 - if(empty($response_result)){
968 - $results = $wpdb->get_results( $wpdb->prepare("SELECT `id`, `query`, `response` FROM %i WHERE 1 and %i = %s", $table,$field, $keyword) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
972 + $field = 'category';
973 + if ( empty( $response_result ) ) {
974 + $results = $wpdb->get_results( $wpdb->prepare( "SELECT `id`, `query`, `response` FROM {$table_sql} WHERE 1 AND `category` = %s", $keyword ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
969 975
970 976
971 977 if(!empty($results)){
972 978 foreach($results as $result){
@@ -1014,10 +1020,10 @@
1014 1020 }
1015 1021
1016 1022
1017 1023
1018 - // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.InterpolatedNotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
1019 - $results = $wpdb->get_results( $wpdb->prepare("SELECT `id`, `query`, `response`, MATCH($qfields) AGAINST(%s IN NATURAL LANGUAGE MODE) as score FROM %i WHERE MATCH($qfields) AGAINST(%s IN NATURAL LANGUAGE MODE) order by score desc limit 15",$keyword,$table,$keyword) );
1024 + // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
1025 + $results = $wpdb->get_results( $wpdb->prepare( "SELECT `id`, `query`, `response`, MATCH({$qfields}) AGAINST(%s IN NATURAL LANGUAGE MODE) as score FROM {$table_sql} WHERE MATCH({$qfields}) AGAINST(%s IN NATURAL LANGUAGE MODE) order by score desc limit 15", $keyword, $keyword ) );
1020 1026
1021 1027 $weight = get_option('qc_bot_str_weight')!=''?get_option('qc_bot_str_weight'):'0.4';
1022 1028
1023 1029 if(!empty($results)){
@@ -1031,14 +1037,14 @@
1031 1037 }
1032 1038 }
1033 1039 }
1034 1040 }
1035 - $field = "keyword";
1036 - if( empty( $response_result ) ){
1041 + $field = 'keyword';
1042 + if ( empty( $response_result ) ) {
1043 +
1044 + $results = $wpdb->get_results( $wpdb->prepare( "SELECT * FROM {$table_sql} WHERE `keyword` REGEXP %s", $keyword ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
1037 1045
1038 - $results = $wpdb->get_results($wpdb->prepare("SELECT * FROM %i WHERE %i REGEXP %s", $table,$field,$keyword)); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1039 1046
1040 -
1041 1047 if(!empty($results)){
1042 1048 foreach($results as $result){
1043 1049 $response_result[] = array('id'=>$result->id,'query'=>$result->query, 'response'=>$result->response, 'score'=>1);
1044 1050 }
@@ -1062,10 +1068,10 @@
1062 1068 $keyword2 = preg_replace('/ \?$/', '?', $keyword);
1063 1069 // Try again with new keyword.
1064 1070 // Repeat the main search logic with $keyword2.
1065 1071 $response_result = array();
1066 - $field = "query";
1067 - $results = $wpdb->get_results( $wpdb->prepare("SELECT `id`, `query`, `response` FROM %i WHERE 1 and %i = %s", $table, $field, $keyword2) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1072 + $field = 'query';
1073 + $results = $wpdb->get_results( $wpdb->prepare( "SELECT `id`, `query`, `response` FROM {$table_sql} WHERE 1 AND `query` = %s", $keyword2 ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
1068 1074 if(!empty($results)){
1069 1075 foreach($results as $result){
1070 1076 $response_result[] = array('id'=>$result->id,'query'=>$result->query, 'response'=>$result->response, 'score'=>1);
1071 1077 }
@@ -1082,9 +1088,9 @@
1082 1088 if(empty($status['data']) || (isset($status['status']) && $status['status']==='fail')){
1083 1089 // Try a partial match if still nothing found.
1084 1090 if(empty($status['data'])) {
1085 1091 $keyword_like = '%' . preg_replace('/[\\s\\?]+/', '%', $keyword) . '%';
1086 - $results = $wpdb->get_results( $wpdb->prepare("SELECT `id`, `query`, `response` FROM %i WHERE `query` LIKE %s", $table, $keyword_like) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching
1092 + $results = $wpdb->get_results( $wpdb->prepare( "SELECT `id`, `query`, `response` FROM {$table_sql} WHERE `query` LIKE %s", $keyword_like ) ); // phpcs:ignore WordPress.DB.DirectDatabaseQuery.DirectQuery, WordPress.DB.DirectDatabaseQuery.NoCaching, WordPress.DB.PreparedSQL.NotPrepared, PluginCheck.Security.DirectDB.UnescapedDBParameter
1087 1093 $response_result = array();
1088 1094 if(!empty($results)){
1089 1095 foreach($results as $result){
1090 1096 $response_result[] = array('id'=>$result->id,'query'=>$result->query, 'response'=>$result->response, 'score'=>1);