PluginProbe
GiveWP – Donation Plugin and Fundraising Platform / 4.18.0
GiveWP – Donation Plugin and Fundraising Platform v4.18.0
4.18.0 4.17.0 4.16.9 4.16.8.1 4.16.8 4.16.7.2 4.16.7.1 4.16.7 4.16.6.1 4.16.6 4.16.5.1 4.16.5 4.16.4 4.16.3 4.16.2 4.16.1 4.16.0 4.15.5 4.15.4 4.15.3 4.15.2 4.15.1 4.15.0 2.3.0 2.3.1 All 257 releases
← All changes | includes/donors/class-give-donor-wall.php +8 -8 4.16.8 → 4.18.0 View file →
@@ -81,8 +81,9 @@
81 81
82 82 /**
83 83 * Displays donors in a grid layout.
84 84 *
85 + * @since 4.16.9 Added additional sanitization to donor output.
85 86 * @since 4.13.2 add strip_shortcodes to the html output
86 87 * @since 4.3.1 remove redundant _give_redirect_form_id() function.
87 88 * @since 3.7.0 Sanitize attributes
88 89 * @since 2.27.0 Moved AJAX nonce verification to ajax_handler method.
@@ -146,9 +147,9 @@
146 147
147 148 $html = ob_get_clean();
148 149
149 150 // Strip shortcodes to prevent execution of user-supplied shortcode syntax.
150 - $html = strip_shortcodes($html);
151 + $html = give_strip_shortcodes_deep($html);
151 152
152 153 // Return only donor html.
153 154 if (
154 155 isset( $atts['only_donor_html'] )
@@ -379,8 +380,10 @@
379 380
380 381 /**
381 382 * Get donation data.
382 383 *
384 + * @since 4.18.0 Read meta values as stored instead of unserializing them, and read the donor
385 + * comment from the fetched rows instead of a per-donation meta lookup.
383 386 * @since 4.16.7.2 Restrict unserialize to prevent object instantiation.
384 387 * @since 2.27.0 Change to read comment from donations meta table
385 388 * @since 2.3.0
386 389 *
@@ -415,9 +418,9 @@
415 418 $temp = [];
416 419
417 420 /* @var stdClass $result */
418 421 foreach ( $results as $result ) {
419 - $temp[ $result->{$donation_id_col} ][ $result->meta_key ] = unserialize( $result->meta_value, [ 'allowed_classes' => false ] );
422 + $temp[ $result->{$donation_id_col} ][ $result->meta_key ] = $result->meta_value;
420 423
421 424 // Set donation date.
422 425 if ( empty( $temp[ $result->{$donation_id_col} ]['donation_date'] ) ) {
423 426 $temp[ $result->{$donation_id_col} ]['donation_date'] = $result->donation_date;
@@ -434,16 +437,13 @@
434 437 'lastname' => $donation_data['_give_donor_billing_last_name'],
435 438 ]
436 439 );
437 440
438 - $temp[$donation_id]['donor_comment'] = give_get_payment_meta(
439 - $donation_id,
440 - DonationMetaKeys::COMMENT
441 - );
441 + $temp[ $donation_id ]['donor_comment'] = $donation_data[ DonationMetaKeys::COMMENT ] ?? '';
442 442 }
443 +
444 + $results = ! empty( $temp ) ? $temp : [];
443 445 }
444 -
445 - $results = ! empty( $temp ) ? $temp : [];
446 446 }
447 447
448 448 return $results;
449 449 }