PluginProbe
GiveWP – Donation Plugin and Fundraising Platform / 4.18.0
GiveWP – Donation Plugin and Fundraising Platform v4.18.0
4.18.0 4.17.0 4.16.9 4.16.8.1 4.16.8 4.16.7.2 4.16.7.1 4.16.7 4.16.6.1 4.16.6 4.16.5.1 4.16.5 4.16.4 4.16.3 4.16.2 4.16.1 4.16.0 4.15.5 4.15.4 4.15.3 4.15.2 4.15.1 4.15.0 2.3.0 2.3.1 All 257 releases
← All changes | includes/donors/class-give-donor-wall.php +10 -9 4.16.2 → 4.18.0 View file →
@@ -81,8 +81,9 @@
81 81
82 82 /**
83 83 * Displays donors in a grid layout.
84 84 *
85 + * @since 4.16.9 Added additional sanitization to donor output.
85 86 * @since 4.13.2 add strip_shortcodes to the html output
86 87 * @since 4.3.1 remove redundant _give_redirect_form_id() function.
87 88 * @since 3.7.0 Sanitize attributes
88 89 * @since 2.27.0 Moved AJAX nonce verification to ajax_handler method.
@@ -146,9 +147,9 @@
146 147
147 148 $html = ob_get_clean();
148 149
149 150 // Strip shortcodes to prevent execution of user-supplied shortcode syntax.
150 - $html = strip_shortcodes($html);
151 + $html = give_strip_shortcodes_deep($html);
151 152
152 153 // Return only donor html.
153 154 if (
154 155 isset( $atts['only_donor_html'] )
@@ -379,9 +380,12 @@
379 380
380 381 /**
381 382 * Get donation data.
382 383 *
383 - * @since 2.27.0 Change to read comment from donations meta table
384 + * @since 4.18.0 Read meta values as stored instead of unserializing them, and read the donor
385 + * comment from the fetched rows instead of a per-donation meta lookup.
386 + * @since 4.16.7.2 Restrict unserialize to prevent object instantiation.
387 + * @since 2.27.0 Change to read comment from donations meta table
384 388 * @since 2.3.0
385 389 *
386 390 * @param array $atts
387 391 *
@@ -414,9 +418,9 @@
414 418 $temp = [];
415 419
416 420 /* @var stdClass $result */
417 421 foreach ( $results as $result ) {
418 - $temp[ $result->{$donation_id_col} ][ $result->meta_key ] = maybe_unserialize( $result->meta_value );
422 + $temp[ $result->{$donation_id_col} ][ $result->meta_key ] = $result->meta_value;
419 423
420 424 // Set donation date.
421 425 if ( empty( $temp[ $result->{$donation_id_col} ]['donation_date'] ) ) {
422 426 $temp[ $result->{$donation_id_col} ]['donation_date'] = $result->donation_date;
@@ -433,16 +437,13 @@
433 437 'lastname' => $donation_data['_give_donor_billing_last_name'],
434 438 ]
435 439 );
436 440
437 - $temp[$donation_id]['donor_comment'] = give_get_payment_meta(
438 - $donation_id,
439 - DonationMetaKeys::COMMENT
440 - );
441 + $temp[ $donation_id ]['donor_comment'] = $donation_data[ DonationMetaKeys::COMMENT ] ?? '';
441 442 }
443 +
444 + $results = ! empty( $temp ) ? $temp : [];
442 445 }
443 -
444 - $results = ! empty( $temp ) ? $temp : [];
445 446 }
446 447
447 448 return $results;
448 449 }