| @@ -81,8 +81,9 @@ | ||
| 81 | 81 | |
| 82 | 82 | /** |
| 83 | 83 | * Displays donors in a grid layout. |
| 84 | 84 | * |
| 85 | + * @since 4.16.9 Added additional sanitization to donor output. | |
| 85 | 86 | * @since 4.13.2 add strip_shortcodes to the html output |
| 86 | 87 | * @since 4.3.1 remove redundant _give_redirect_form_id() function. |
| 87 | 88 | * @since 3.7.0 Sanitize attributes |
| 88 | 89 | * @since 2.27.0 Moved AJAX nonce verification to ajax_handler method. |
| @@ -146,9 +147,9 @@ | ||
| 146 | 147 | |
| 147 | 148 | $html = ob_get_clean(); |
| 148 | 149 | |
| 149 | 150 | // Strip shortcodes to prevent execution of user-supplied shortcode syntax. |
| 150 | - $html = strip_shortcodes($html); | |
| 151 | + $html = give_strip_shortcodes_deep($html); | |
| 151 | 152 | |
| 152 | 153 | // Return only donor html. |
| 153 | 154 | if ( |
| 154 | 155 | isset( $atts['only_donor_html'] ) |
| @@ -379,9 +380,12 @@ | ||
| 379 | 380 | |
| 380 | 381 | /** |
| 381 | 382 | * Get donation data. |
| 382 | 383 | * |
| 383 | - * @since 2.27.0 Change to read comment from donations meta table | |
| 384 | + * @since 4.18.0 Read meta values as stored instead of unserializing them, and read the donor | |
| 385 | + * comment from the fetched rows instead of a per-donation meta lookup. | |
| 386 | + * @since 4.16.7.2 Restrict unserialize to prevent object instantiation. | |
| 387 | + * @since 2.27.0 Change to read comment from donations meta table | |
| 384 | 388 | * @since 2.3.0 |
| 385 | 389 | * |
| 386 | 390 | * @param array $atts |
| 387 | 391 | * |
| @@ -414,9 +418,9 @@ | ||
| 414 | 418 | $temp = []; |
| 415 | 419 | |
| 416 | 420 | /* @var stdClass $result */ |
| 417 | 421 | foreach ( $results as $result ) { |
| 418 | - $temp[ $result->{$donation_id_col} ][ $result->meta_key ] = maybe_unserialize( $result->meta_value ); | |
| 422 | + $temp[ $result->{$donation_id_col} ][ $result->meta_key ] = $result->meta_value; | |
| 419 | 423 | |
| 420 | 424 | // Set donation date. |
| 421 | 425 | if ( empty( $temp[ $result->{$donation_id_col} ]['donation_date'] ) ) { |
| 422 | 426 | $temp[ $result->{$donation_id_col} ]['donation_date'] = $result->donation_date; |
| @@ -433,16 +437,13 @@ | ||
| 433 | 437 | 'lastname' => $donation_data['_give_donor_billing_last_name'], |
| 434 | 438 | ] |
| 435 | 439 | ); |
| 436 | 440 | |
| 437 | - $temp[$donation_id]['donor_comment'] = give_get_payment_meta( | |
| 438 | - $donation_id, | |
| 439 | - DonationMetaKeys::COMMENT | |
| 440 | - ); | |
| 441 | + $temp[ $donation_id ]['donor_comment'] = $donation_data[ DonationMetaKeys::COMMENT ] ?? ''; | |
| 441 | 442 | } |
| 443 | + | |
| 444 | + $results = ! empty( $temp ) ? $temp : []; | |
| 442 | 445 | } |
| 443 | - | |
| 444 | - $results = ! empty( $temp ) ? $temp : []; | |
| 445 | 446 | } |
| 446 | 447 | |
| 447 | 448 | return $results; |
| 448 | 449 | } |