PluginProbe
King Addons for Elementor – 100+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce Builder, Mega Menu, Popup Builder / 51.1.87
King Addons for Elementor – 100+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce Builder, Mega Menu, Popup Builder v51.1.87
51.1.87 51.1.86 51.1.84 51.1.85 51.1.83 51.1.82 51.1.81 51.1.79 51.1.78 51.1.77 51.1.76 51.1.74 51.1.75 51.1.65 51.1.64 51.1.63 trunk 51.1.14 51.1.2 51.1.35 51.1.36 51.1.37 51.1.38 51.1.39 51.1.44 All 41 releases
← All changes | includes/widgets/Search/Search_Ajax.php +12 -12 51.1.14 → 51.1.87 View file →
@@ -33,27 +33,27 @@
33 33 }
34 34
35 35 $tax_query = '';
36 36
37 - if ($_POST['king_addons_category'] && $_POST['king_addons_category'] != '') {
37 + if (isset($_POST['king_addons_category']) && $_POST['king_addons_category'] != '') {
38 38 $tax_query = array(
39 39 array(
40 - 'taxonomy' => $_POST['king_addons_option_post_type'],
40 + 'taxonomy' => sanitize_text_field($_POST['king_addons_option_post_type'] ?? ''),
41 41 'field' => 'term_id',
42 42 'terms' => sanitize_text_field($_POST['king_addons_category']),
43 43 ),
44 44 );
45 - } else if ($_POST['king_addons_category'] == 0 && $_POST['king_addons_query_type'] != 'all') {
45 + } else if (isset($_POST['king_addons_category']) && $_POST['king_addons_category'] == 0 && isset($_POST['king_addons_query_type']) && $_POST['king_addons_query_type'] != 'all') {
46 46 if (!empty($_POST['king_addons_option_post_type'])) {
47 47 $tax_query = array(
48 48 array(
49 - 'taxonomy' => $_POST['king_addons_option_post_type'],
49 + 'taxonomy' => sanitize_text_field($_POST['king_addons_option_post_type']),
50 50 'field' => 'term_id',
51 51 'terms' => sanitize_text_field($_POST['king_addons_category']),
52 52 ),
53 53 );
54 54 } else {
55 - $taxonomy_type_string = $_POST['king_addons_taxonomy_type'];
55 + $taxonomy_type_string = sanitize_text_field($_POST['king_addons_taxonomy_type'] ?? '');
56 56
57 57 if (strpos($taxonomy_type_string, ' ') !== false) {
58 58 $taxonomy_types = explode(' ', $taxonomy_type_string);
59 59 $tax_query = [
@@ -68,9 +68,9 @@
68 68 }
69 69 } else {
70 70 $tax_query = array(
71 71 array(
72 - 'taxonomy' => $_POST['king_addons_taxonomy_type'],
72 + 'taxonomy' => sanitize_text_field($_POST['king_addons_taxonomy_type'] ?? ''),
73 73 'operator' => 'EXISTS',
74 74 ),
75 75 );
76 76 }
@@ -76,9 +76,9 @@
76 76 }
77 77 }
78 78 }
79 79
80 - if ($_POST['king_addons_category'] == 0 || $_POST['king_addons_query_type'] === 'all') {
80 + if ((isset($_POST['king_addons_category']) && $_POST['king_addons_category'] == 0) || (isset($_POST['king_addons_query_type']) && $_POST['king_addons_query_type'] === 'all')) {
81 81 $tax_query = [];
82 82 }
83 83
84 84 $can_view_protected_posts = current_user_can('read_private_posts');
@@ -121,16 +121,16 @@
121 121 href="<?php echo $post_url; ?>"><?php the_title(); ?></a>
122 122 <?php if ($can_show_content && 'yes' === sanitize_text_field($_POST['king_addons_show_description'])) : ?>
123 123 <p class="king-addons-ajax-desc">
124 124 <a target="<?php echo $target; ?>" href="<?php echo $post_url; ?>">
125 - <?php echo wp_trim_words(get_the_content(), sanitize_text_field($_POST['king_addons_number_of_words'])); ?>
125 + <?php echo wp_trim_words(wp_kses_post(get_the_content()), sanitize_text_field($_POST['king_addons_number_of_words'])); ?>
126 126 </a>
127 127 </p>
128 128 <?php endif; ?>
129 - <?php if ($can_show_content && sanitize_text_field($_POST['king_addons_show_view_result_btn'])) : ?>
129 + <?php if ($can_show_content && sanitize_text_field($_POST['king_addons_show_view_result_btn'] ?? '')) : ?>
130 130 <a target="<?php echo $target; ?>" class="king-addons-view-result"
131 131 href="<?php echo $post_url; ?>">
132 - <?php echo sanitize_text_field($_POST['king_addons_view_result_text']); ?>
132 + <?php echo esc_html(sanitize_text_field($_POST['king_addons_view_result_text'] ?? '')); ?>
133 133 </a>
134 134 <?php endif; ?>
135 135 </div>
136 136 </li>
@@ -139,10 +139,10 @@
139 139
140 140 wp_reset_postdata();
141 141
142 142 else :
143 - if (sanitize_text_field($_POST['king_addons_search_results_offset']) <= 0) {
144 - echo '<p class="king-addons-no-results">' . sanitize_text_field($_POST['king_addons_no_results']) . '</p>';
143 + if (sanitize_text_field($_POST['king_addons_search_results_offset'] ?? '0') <= 0) {
144 + echo '<p class="king-addons-no-results">' . esc_html(sanitize_text_field($_POST['king_addons_no_results'] ?? '')) . '</p>';
145 145 }
146 146 endif;
147 147
148 148 die();