PluginProbe
EmailKit – Email Customizer for WooCommerce & WP / 1.6.9
EmailKit – Email Customizer for WooCommerce & WP v1.6.9
1.6.9 1.6.8 1.6.7 trunk 1.0.0 1.2.0 1.4.0 1.4.5 1.5.0 1.5.1 1.5.2 1.5.3 1.5.4 1.5.5 1.5.6 1.5.7 1.5.8 1.5.9 1.6.0 1.6.1 1.6.2 1.6.3 1.6.4 1.6.5 1.6.6
← All changes | includes/Admin/Api/TemplateData.php +28 -6 1.6.2 → 1.6.9 View file →
@@ -1,8 +1,10 @@
1 1 <?php
2 2
3 3 namespace EmailKit\Admin\Api;
4 4
5 +use EmailKit\Admin\Emails\Helpers\Utils;
6 +
5 7 defined('ABSPATH') || exit;
6 8 class TemplateData
7 9 {
8 10
@@ -26,9 +28,9 @@
26 28
27 29 if (!wp_verify_nonce($request->get_header( 'X-WP-Nonce' ), 'wp_rest')) {
28 30 return [
29 31 'status' => 'fail',
30 - 'message' => ['Nonce mismatch.']
32 + 'message' => [esc_html__( 'Nonce mismatch.', 'emailkit' )]
31 33 ];
32 34 }
33 35
34 36 if (!is_user_logged_in() || !current_user_can( 'manage_options' )) {
@@ -33,9 +35,9 @@
33 35
34 36 if (!is_user_logged_in() || !current_user_can( 'manage_options' )) {
35 37 return [
36 38 'status' => 'fail',
37 - 'message' => ['Access denied.']
39 + 'message' => [esc_html__( 'Access denied.', 'emailkit' )]
38 40 ];
39 41 }
40 42 $template = '';
41 43 $html = '';
@@ -44,11 +46,30 @@
44 46 $message = '';
45 47
46 48
47 49
48 - if(!empty($request->get_param( 'emailkit-editor-template' ) && trim($request->get_param( 'emailkit-editor-template' )) !== '')){
49 - $template = file_get_contents($request->get_param( 'emailkit-editor-template' ))??'';
50 - $html = file_get_contents(str_replace( "content.json", "content.html", $request->get_param( 'emailkit-editor-template' )))??'';
50 + if (!empty($request->get_param('emailkit-editor-template')) && trim($request->get_param('emailkit-editor-template')) !== '') {
51 + $template_path = $request->get_param('emailkit-editor-template');
52 + $allowed_base_path = wp_upload_dir()['basedir'] . '/emailkit/templates/';
53 + $real_path = realpath($template_path);
54 + if ($real_path === false || strpos($real_path, realpath($allowed_base_path)) !== 0) {
55 + return [
56 + 'status' => 'fail',
57 + 'message' => [__('Invalid template path', 'emailkit')]
58 + ];
59 + }
60 +
61 + $template = file_exists($real_path) ? file_get_contents($real_path) : '';
62 + $template = Utils::normalize_template_asset_urls($template);
63 + $html_path = str_replace("content.json", "content.html", $real_path);
64 +
65 + // Validate HTML path as well
66 + $real_html_path = realpath($html_path);
67 + if ($real_html_path !== false && strpos($real_html_path, realpath($allowed_base_path)) === 0) {
68 +
69 + $html = file_exists($real_html_path) ? file_get_contents($real_html_path) : '';
70 + $html = Utils::normalize_template_asset_urls($html);
71 + }
51 72 }
52 73
53 74 $subject = !empty($request->get_param( 'emailkit_template_title' ))? trim($request->get_param( 'emailkit_template_title' )) : null;
54 75
@@ -60,9 +81,9 @@
60 81 $data = array(
61 82 'post_type' => 'emailkit',
62 83 'post_status' => 'publish',
63 84 'post_author' => get_current_user_id(),
64 - 'post_title' => $subject !== '' ? $subject : "New Template ".uniqid(),
85 + 'post_title' => $subject !== '' ? $subject : esc_html__( 'New Template', 'emailkit' ) . ' ' . uniqid(),
65 86 'meta_input' => array(
66 87 'emailkit_template_content_html' => $html,
67 88 'emailkit_template_content_object' => $template,
68 89 'emailkit_email_type' => $request->get_param('emailkit_email_type'),
@@ -123,5 +144,6 @@
123 144 update_post_meta($id, 'emailkit_template_status', 'inactive');
124 145 }
125 146 }
126 147 }
148 +
127 149 }