| @@ -399,26 +399,25 @@ | ||
| 399 | 399 | |
| 400 | 400 | // On network wide active installs, we need to switch to main blog mostly for posts permalinks and thumbnails |
| 401 | 401 | $blog_id = gamipress_switch_to_main_site_if_network_wide_active(); |
| 402 | 402 | |
| 403 | + // Sanitization | |
| 404 | + $limit = absint( $limit ); | |
| 405 | + $offset = absint( $offset ); | |
| 406 | + $order = gamipress_validate_from_array( strtoupper( $order ), array( 'ASC', 'DESC' ), 'DESC' ); | |
| 407 | + | |
| 403 | 408 | // Turn no attributes to false |
| 404 | - if( $current_user === 'no' ) { | |
| 409 | + if( $current_user === 'no' ) | |
| 405 | 410 | $current_user = false; |
| 406 | - } | |
| 407 | 411 | |
| 408 | - if( $wpms === 'no' ) { | |
| 412 | + if( $wpms === 'no' ) | |
| 409 | 413 | $wpms = false; |
| 410 | - } | |
| 411 | 414 | |
| 412 | 415 | // Force to set current user as user ID |
| 413 | - if( $current_user ) { | |
| 414 | - $user_id = get_current_user_id(); | |
| 415 | - } | |
| 416 | + if( $current_user ) $user_id = get_current_user_id(); | |
| 416 | 417 | |
| 417 | 418 | // Get the current user if one wasn't specified |
| 418 | - if( ! $user_id ) { | |
| 419 | - $user_id = get_current_user_id(); | |
| 420 | - } | |
| 419 | + if( ! $user_id ) $user_id = get_current_user_id(); | |
| 421 | 420 | |
| 422 | 421 | // Ensure user ID as int |
| 423 | 422 | $user_id = absint( $user_id ); |
| 424 | 423 | |
| @@ -503,10 +502,10 @@ | ||
| 503 | 502 | $query_args = array( |
| 504 | 503 | 'post_type' => $type, |
| 505 | 504 | 'orderby' => $orderby, |
| 506 | 505 | 'order' => $order, |
| 507 | - 'posts_per_page' => absint( $limit ), | |
| 508 | - 'offset' => absint( $offset ), | |
| 506 | + 'posts_per_page' => $limit, | |
| 507 | + 'offset' => $offset, | |
| 509 | 508 | 'post_status' => 'publish', |
| 510 | 509 | 'post__in' => array(), |
| 511 | 510 | 'post__not_in' => array_diff( $hidden, $earned_ids ) |
| 512 | 511 | ); |