| @@ -7167,9 +7167,10 @@ | ||
| 7167 | 7167 | { |
| 7168 | 7168 | $s = $this->get_settings_for_display(); |
| 7169 | 7169 | $author = !empty($s['query_author']) ? implode(',', $s['query_author']) : ''; |
| 7170 | 7170 | $paged = get_query_var('paged') ? get_query_var('paged') : (get_query_var('page') ? get_query_var('page') : 1); |
| 7171 | - $offset = ($paged - 1) * $s['query_posts_per_page'] + (empty($s['query_offset']) ? 0 : $s['query_offset']); | |
| 7171 | + $offset = ($paged - 1) * Core::jsNumber($s, 'query_posts_per_page', 10) | |
| 7172 | + + (empty($s['query_offset']) ? 0 : Core::jsNumber($s, 'query_offset', 0)); | |
| 7172 | 7173 | |
| 7173 | 7174 | // Remove premium-only randomize if not available |
| 7174 | 7175 | if (!king_addons_freemius()->can_use_premium_code__premium_only()) { |
| 7175 | 7176 | $s['query_randomize'] = ''; |
| @@ -7249,33 +7250,35 @@ | ||
| 7249 | 7250 | } |
| 7250 | 7251 | |
| 7251 | 7252 | public function get_animation_class($data, $object) |
| 7252 | 7253 | { |
| 7253 | - $class = ''; | |
| 7254 | - if ('none' !== $data[$object . '_animation']) { | |
| 7255 | - $class .= ' king-addons-' . $object . '-' . $data[$object . '_animation']; | |
| 7256 | - $class .= ' king-addons-anim-size-' . $data[$object . '_animation_size']; | |
| 7257 | - $class .= ' king-addons-animation-timing-' . $data[$object . '_animation_timing']; | |
| 7258 | - if ('yes' === $data[$object . '_animation_tr']) $class .= ' king-addons-anim-transparency'; | |
| 7254 | + $animation = Grid_Ajax_Security::sanitize_animation($data[$object . '_animation'] ?? 'none'); | |
| 7255 | + if ('none' === $animation) { | |
| 7256 | + return ''; | |
| 7259 | 7257 | } |
| 7258 | + | |
| 7259 | + $class = ' king-addons-' . sanitize_html_class((string) $object) . '-' . $animation; | |
| 7260 | + $class .= ' king-addons-anim-size-' . Grid_Ajax_Security::sanitize_animation_size($data[$object . '_animation_size'] ?? 'large'); | |
| 7261 | + $class .= ' king-addons-animation-timing-' . Grid_Ajax_Security::sanitize_animation_timing($data[$object . '_animation_timing'] ?? 'ease-default'); | |
| 7262 | + | |
| 7263 | + if ('yes' === Grid_Ajax_Security::sanitize_yes_no_switcher($data[$object . '_animation_tr'] ?? '')) { | |
| 7264 | + $class .= ' king-addons-anim-transparency'; | |
| 7265 | + } | |
| 7266 | + | |
| 7260 | 7267 | return $class; |
| 7261 | 7268 | } |
| 7262 | 7269 | |
| 7263 | 7270 | public function get_image_effect_class($s) |
| 7264 | 7271 | { |
| 7272 | + $effect = Grid_Ajax_Security::sanitize_image_effect($s['image_effects'] ?? 'none'); | |
| 7265 | 7273 | $class = ''; |
| 7266 | - if (!king_addons_freemius()->can_use_premium_code__premium_only()) { | |
| 7267 | - if (in_array($s['image_effects'], ['pro-zi', 'pro-zo', 'pro-go', 'pro-bo'])) { | |
| 7268 | - $s['image_effects'] = 'none'; | |
| 7269 | - } | |
| 7274 | + if ('none' !== $effect) { | |
| 7275 | + $class .= ' king-addons-' . $effect; | |
| 7270 | 7276 | } |
| 7271 | - if ('none' !== $s['image_effects']) { | |
| 7272 | - $class .= ' king-addons-' . $s['image_effects']; | |
| 7273 | - } | |
| 7274 | - if ('slide' !== $s['image_effects']) { | |
| 7275 | - $class .= ' king-addons-effect-size-' . $s['image_effects_size']; | |
| 7277 | + if ('slide' !== $effect) { | |
| 7278 | + $class .= ' king-addons-effect-size-' . Grid_Ajax_Security::sanitize_image_effect_size($s['image_effects_size'] ?? 'medium'); | |
| 7276 | 7279 | } else { |
| 7277 | - $class .= ' king-addons-effect-dir-' . $s['image_effects_direction']; | |
| 7280 | + $class .= ' king-addons-effect-dir-' . Grid_Ajax_Security::sanitize_image_effect_direction($s['image_effects_direction'] ?? 'bottom'); | |
| 7278 | 7281 | } |
| 7279 | 7282 | return $class; |
| 7280 | 7283 | } |
| 7281 | 7284 | |
| @@ -7300,9 +7303,9 @@ | ||
| 7300 | 7303 | $post_id = get_the_ID(); |
| 7301 | 7304 | } |
| 7302 | 7305 | |
| 7303 | 7306 | $overlay_url = $post_id ? get_the_permalink($post_id) : '#'; |
| 7304 | - echo '<div class="king-addons-grid-media-hover-bg ' . $this->get_animation_class($s, 'overlay') . '" data-url="' . esc_url($overlay_url) . '">'; | |
| 7307 | + echo '<div class="king-addons-grid-media-hover-bg ' . esc_attr($this->get_animation_class($s, 'overlay')) . '" data-url="' . esc_url($overlay_url) . '">'; | |
| 7305 | 7308 | if (king_addons_freemius()->can_use_premium_code__premium_only()) { |
| 7306 | 7309 | if ('' !== $s['overlay_image']['url']) { |
| 7307 | 7310 | echo '<img src="' . esc_url($s['overlay_image']['url']) . '">'; |
| 7308 | 7311 | } |
| @@ -7889,9 +7892,9 @@ | ||
| 7889 | 7892 | 'selector' => '.king-addons-grid-image-wrap', |
| 7890 | 7893 | 'iframeMaxWidth' => '60%', |
| 7891 | 7894 | 'hash' => false, |
| 7892 | 7895 | 'autoplay' => $s['lightbox_popup_autoplay'], |
| 7893 | - 'pause' => $s['lightbox_popup_pause'] * 1000, | |
| 7896 | + 'pause' => Core::jsNumber($s, 'lightbox_popup_pause', 5) * 1000, | |
| 7894 | 7897 | 'progressBar' => $s['lightbox_popup_progressbar'], |
| 7895 | 7898 | 'counter' => $s['lightbox_popup_counter'], |
| 7896 | 7899 | 'controls' => $s['lightbox_popup_arrows'], |
| 7897 | 7900 | 'getCaptionFromTitleOrAlt' => false, |
| @@ -8022,9 +8025,9 @@ | ||
| 8022 | 8025 | |
| 8023 | 8026 | echo '<article class="' . esc_attr($post_class) . '">'; |
| 8024 | 8027 | echo '<div class="king-addons-grid-item-inner">'; |
| 8025 | 8028 | $this->get_elements_by_location('above', $s, get_the_ID()); |
| 8026 | - echo '<div class="king-addons-grid-media-wrap' . $this->get_image_effect_class($s) . ' ">'; | |
| 8029 | + echo '<div class="king-addons-grid-media-wrap' . esc_attr($this->get_image_effect_class($s)) . ' ">'; | |
| 8027 | 8030 | $this->render_post_thumbnail($s); |
| 8028 | 8031 | echo '<div class="king-addons-grid-media-hover king-addons-animation-wrap">'; |
| 8029 | 8032 | $this->render_media_overlay($s); |
| 8030 | 8033 | $this->get_elements_by_location('over', $s, get_the_ID()); |