| @@ -1,10 +1,10 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | /* |
| 3 | 3 | Plugin Name: iframe |
| 4 | 4 | Plugin URI: http://wordpress.org/plugins/iframe/ |
| 5 | -Description: [iframe src="http://www.youtube.com/embed/7_nAZQt9qu0" width="100%" height="500"] shortcode | |
| 6 | -Version: 6.0 | |
| 5 | +Description: [iframe src="http://www.youtube.com/embed/dUpTjDqjQoo" width="100%" height="500"] shortcode | |
| 6 | +Version: 4.8 | |
| 7 | 7 | Author: webvitaly |
| 8 | 8 | Author URI: http://web-profile.net/wordpress/plugins/ |
| 9 | 9 | License: GPLv3 |
| 10 | 10 | */ |
| @@ -12,31 +12,36 @@ | ||
| 12 | 12 | if ( ! defined( 'ABSPATH' ) ) { // Avoid direct calls to this file and prevent full path disclosure |
| 13 | 13 | exit; |
| 14 | 14 | } |
| 15 | 15 | |
| 16 | -define('IFRAME_PLUGIN_VERSION', '6.0'); | |
| 16 | +define('IFRAME_PLUGIN_VERSION', '4.8'); | |
| 17 | 17 | |
| 18 | -// Load settings page functionality | |
| 19 | -require_once( plugin_dir_path( __FILE__ ) . 'iframe-settings.php' ); | |
| 20 | - | |
| 21 | - | |
| 22 | 18 | function iframe_plugin_add_shortcode_cb( $atts ) { |
| 23 | - // Get plugin settings | |
| 24 | - $settings = iframe_plugin_get_settings(); | |
| 25 | - | |
| 26 | 19 | $defaults = array( |
| 27 | - //'src' => 'http://www.youtube.com/embed/7_nAZQt9qu0', | |
| 20 | + 'src' => 'http://www.youtube.com/embed/dUpTjDqjQoo', | |
| 28 | 21 | 'width' => '100%', |
| 29 | 22 | 'height' => '500', |
| 30 | 23 | 'scrolling' => 'yes', |
| 31 | 24 | 'class' => 'iframe-class', |
| 32 | - 'frameborder' => '0', | |
| 33 | - 'loading' => $settings['loading'] // Global setting from settings array | |
| 25 | + 'frameborder' => '0' | |
| 34 | 26 | ); |
| 35 | 27 | |
| 36 | - if ( ! is_array( $atts ) ) { | |
| 37 | - $atts = array(); | |
| 38 | - } | |
| 28 | + $allowed_tags = array( | |
| 29 | + 'h1' => array(), | |
| 30 | + 'h2' => array(), | |
| 31 | + 'h3' => array(), | |
| 32 | + 'h4' => array(), | |
| 33 | + 'h5' => array(), | |
| 34 | + 'h6' => array(), | |
| 35 | + 'p' => array(), | |
| 36 | + 'a' => array( | |
| 37 | + 'href' => true, | |
| 38 | + 'title' => true, | |
| 39 | + ), | |
| 40 | + 'br' => array(), | |
| 41 | + 'em' => array(), | |
| 42 | + 'strong' => array() | |
| 43 | + ); | |
| 39 | 44 | |
| 40 | 45 | foreach ( $defaults as $default => $value ) { // add defaults |
| 41 | 46 | if ( ! @array_key_exists( $default, $atts ) ) { // mute warning with "@" when no params at all |
| 42 | 47 | $atts[$default] = $value; |
| @@ -48,29 +53,20 @@ | ||
| 48 | 53 | foreach( $atts as $attr => $value ) { |
| 49 | 54 | if ( strtolower($attr) == 'src' ) { // sanitize url |
| 50 | 55 | $value = esc_url( $value ); |
| 51 | 56 | } |
| 52 | - | |
| 53 | - // Remove 'srcdoc' attribute | |
| 54 | - if ( strtolower($attr) == 'srcdoc' ) { | |
| 55 | - continue; | |
| 57 | + if ( strtolower($attr) == 'srcdoc' ) { // sanitize html | |
| 58 | + $value = wp_kses( $value, $allowed_tags ); | |
| 59 | + $value = esc_html( $value ); | |
| 56 | 60 | } |
| 57 | - | |
| 58 | - // Skip attributes starting with "on". Examples: onload, onmouseover, onfocus, onpageshow, onclick | |
| 59 | - if ( strpos( strtolower( $attr ), 'on' ) === 0 ) { | |
| 60 | - continue; | |
| 61 | + // Remove all attributes starting with "on". Examples: onload, onmouseover, onfocus, onpageshow, onclick | |
| 62 | + if ( strpos( strtolower( $attr ), 'on' ) !== 0 ) { | |
| 63 | + if ( $value != '' ) { // adding all attributes | |
| 64 | + $html .= ' ' . esc_attr( $attr ) . '="' . esc_attr( $value ) . '"'; | |
| 65 | + } else { // adding empty attributes | |
| 66 | + $html .= ' ' . esc_attr( $attr ); | |
| 67 | + } | |
| 61 | 68 | } |
| 62 | - | |
| 63 | - // Skip loading attribute if set to 'none' (browser default) | |
| 64 | - if ( strtolower($attr) == 'loading' && strtolower($value) == 'none' ) { | |
| 65 | - continue; | |
| 66 | - } | |
| 67 | - | |
| 68 | - if ($value !== '') { // adding all attributes | |
| 69 | - $html .= ' ' . esc_attr($attr) . '="' . esc_attr($value) . '"'; | |
| 70 | - } else { // adding empty attributes | |
| 71 | - $html .= ' ' . esc_attr($attr); | |
| 72 | - } | |
| 73 | 69 | } |
| 74 | 70 | $html .= '></iframe>'."\n"; |
| 75 | 71 | |
| 76 | 72 | if ( isset( $atts["same_height_as"] ) ) { |
| @@ -94,9 +90,10 @@ | ||
| 94 | 90 | function iframe_plugin_row_meta_cb( $links, $file ) { |
| 95 | 91 | if ( $file == plugin_basename( __FILE__ ) ) { |
| 96 | 92 | $row_meta = array( |
| 97 | 93 | 'support' => '<a href="http://web-profile.net/wordpress/plugins/iframe/" target="_blank">' . __( 'Iframe', 'iframe' ) . '</a>', |
| 98 | - 'donate' => '<a href="http://web-profile.net/donate/" target="_blank">' . __( 'Donate', 'iframe' ) . '</a>' | |
| 94 | + 'donate' => '<a href="http://web-profile.net/donate/" target="_blank">' . __( 'Donate', 'iframe' ) . '</a>', | |
| 95 | + 'pro' => '<a href="https://1.envato.market/Ym5aq" target="_blank">' . __( 'Advanced iFrame Pro', 'iframe' ) . '</a>' | |
| 99 | 96 | ); |
| 100 | 97 | $links = array_merge( $links, $row_meta ); |
| 101 | 98 | } |
| 102 | 99 | return (array) $links; |