PluginProbe
GiveWP – Donation Plugin and Fundraising Platform / 4.18.0
GiveWP – Donation Plugin and Fundraising Platform v4.18.0
4.18.0 4.17.0 4.16.9 4.16.8.1 4.16.8 4.16.7.2 4.16.7.1 4.16.7 4.16.6.1 4.16.6 4.16.5.1 4.16.5 4.16.4 4.16.3 4.16.2 4.16.1 4.16.0 4.15.5 4.15.4 4.15.3 4.15.2 4.15.1 4.15.0 2.3.0 2.3.1 All 257 releases
← All changes | src/Campaigns/Shortcodes/CampaignGridShortcode.php +13 -4 4.16.0 → 4.18.0 View file →
@@ -64,8 +64,9 @@
64 64 wp_enqueue_style('givewp-design-system-foundation');
65 65 }
66 66
67 67 /**
68 + * @since 4.18.0 Sanitize string attributes and restrict enumerated values.
68 69 * @since 4.2.0
69 70 */
70 71 private function parseAttributes($atts): array
71 72 {
@@ -81,16 +82,24 @@
81 82 'filter_by' => null,
82 83 ], $atts, 'givewp_campaign_grid');
83 84
84 85 return [
85 - 'layout' => $atts['layout'],
86 + 'layout' => $this->pickAllowed($atts['layout'], ['full', 'double', 'triple'], 'full'),
86 87 'showImage' => filter_var($atts['show_image'], FILTER_VALIDATE_BOOLEAN),
87 88 'showDescription' => filter_var($atts['show_description'], FILTER_VALIDATE_BOOLEAN),
88 89 'showGoal' => filter_var($atts['show_goal'], FILTER_VALIDATE_BOOLEAN),
89 - 'sortBy' => $atts['sort_by'],
90 - 'orderBy' => $atts['order_by'],
91 - 'filterBy' => $atts['filter_by'],
90 + 'sortBy' => $this->pickAllowed($atts['sort_by'], ['date', 'amount', 'donations', 'donors'], 'date'),
91 + 'orderBy' => $this->pickAllowed($atts['order_by'], ['asc', 'desc'], 'desc'),
92 + 'filterBy' => $atts['filter_by'] ? sanitize_text_field($atts['filter_by']) : $atts['filter_by'],
92 93 'perPage' => (int)$atts['per_page'],
93 94 'showPagination' => filter_var($atts['show_pagination'], FILTER_VALIDATE_BOOLEAN),
94 95 ];
96 + }
97 +
98 + /**
99 + * @since 4.18.0
100 + */
101 + private function pickAllowed($value, array $allowed, $default): string
102 + {
103 + return in_array($value, $allowed, true) ? $value : $default;
95 104 }
96 105 }