← All changes
|
inc/admin/views/meta-boxes/lp-meta-box-functions.php
+95
-60
4.1.6.9
→
4.4.10
View file →
| @@ -1,6 +1,36 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | /** |
| 3 | + * Resolve post ID for meta box rendering. | |
| 4 | + * | |
| 5 | + * In some admin/AJAX contexts, global $post can be null. | |
| 6 | + * Returning 0 allows callers to safely fall back to default values. | |
| 7 | + * | |
| 8 | + * @return int | |
| 9 | + */ | |
| 10 | +function lp_meta_box_get_post_id() { | |
| 11 | + global $thepostid, $post; | |
| 12 | + | |
| 13 | + if ( ! empty( $thepostid ) ) { | |
| 14 | + return absint( $thepostid ); | |
| 15 | + } | |
| 16 | + | |
| 17 | + if ( is_object( $post ) && ! empty( $post->ID ) ) { | |
| 18 | + $thepostid = absint( $post->ID ); | |
| 19 | + | |
| 20 | + return $thepostid; | |
| 21 | + } | |
| 22 | + | |
| 23 | + $resolved_post_id = absint( get_the_ID() ); | |
| 24 | + | |
| 25 | + if ( $resolved_post_id > 0 ) { | |
| 26 | + $thepostid = $resolved_post_id; | |
| 27 | + } | |
| 28 | + | |
| 29 | + return $resolved_post_id; | |
| 30 | +} | |
| 31 | + | |
| 32 | +/** | |
| 3 | 33 | * Output a text input box. |
| 4 | 34 | * |
| 5 | 35 | * @param array $field |
| 6 | 36 | */ |
| @@ -6,9 +36,9 @@ | ||
| 6 | 36 | */ |
| 7 | 37 | function lp_meta_box_text_input_field( $field ) { |
| 8 | 38 | global $thepostid, $post; |
| 9 | 39 | |
| 10 | - $thepostid = empty( $thepostid ) ? $post->ID : $thepostid; | |
| 40 | + $thepostid = lp_meta_box_get_post_id(); | |
| 11 | 41 | $field['placeholder'] = esc_attr( $field['placeholder'] ?? '' ); |
| 12 | 42 | $field['class'] = esc_attr( $field['class'] ?? '' ); |
| 13 | 43 | $field['style'] = esc_attr( $field['style'] ?? '' ); |
| 14 | 44 | $wrapper_class = esc_attr( $field['wrapper_class'] ?? '' ); |
| @@ -16,10 +46,10 @@ | ||
| 16 | 46 | /** |
| 17 | 47 | * If you want to set default value for input text |
| 18 | 48 | * You must us hook default_{$meta_type}_metadata | Read more get_metadata_default() function |
| 19 | 49 | */ |
| 20 | - $value_exists = LP_Database::getInstance()->check_key_postmeta_exists( $thepostid, $field['id'] ); | |
| 21 | - $value = get_post_meta( $thepostid, $field['id'], true ); | |
| 50 | + $value_exists = $thepostid > 0 ? LP_Database::getInstance()->check_key_postmeta_exists( $thepostid, $field['id'] ) : false; | |
| 51 | + $value = $thepostid > 0 ? get_post_meta( $thepostid, $field['id'], true ) : ''; | |
| 22 | 52 | $field['value'] = $value_exists ? $value : ( $field['default'] ?? '' ); |
| 23 | 53 | $field['id'] = esc_attr( $field['id'] ?? '' ); |
| 24 | 54 | $field['type_input'] = esc_attr( $field['type_input'] ?? 'text' ); |
| 25 | 55 | $field['desc_tip'] = esc_attr( $field['desc_tip'] ?? '' ); |
| @@ -35,18 +65,20 @@ | ||
| 35 | 65 | |
| 36 | 66 | $custom_attributes_str = implode( ' ', $custom_attributes ); |
| 37 | 67 | ?> |
| 38 | 68 | |
| 39 | - <div class="form-field <?php echo $field['id'] . '_field ' . $wrapper_class; ?>"> | |
| 40 | - <label for="<?php echo $field['id']; ?>"><?php echo wp_kses_post( $field['label'] ); ?></label> | |
| 41 | - <input type="<?php echo $field['type_input']; ?>" | |
| 42 | - class="<?php echo $field['class']; ?>" | |
| 43 | - style="<?php echo $field['style']; ?>" | |
| 44 | - name="<?php echo $field['id']; ?>" | |
| 45 | - id="<?php echo $field['id']; ?>" | |
| 46 | - value="<?php echo $field['value']; ?>" | |
| 47 | - placeholder="<?php echo $field['placeholder']; ?>" <?php echo $custom_attributes_str; ?> /> | |
| 48 | - | |
| 69 | + <div class="form-field <?php echo esc_attr( $field['id'] . '_field ' . $wrapper_class ); ?>"> | |
| 70 | + <label for="<?php echo esc_attr( $field['id'] ); ?>"> | |
| 71 | + <?php echo wp_kses_post( $field['label'] ); ?> | |
| 72 | + </label> | |
| 73 | + <input type="<?php echo esc_attr( $field['type_input'] ); ?>" | |
| 74 | + class="<?php echo esc_attr( $field['class'] ); ?>" | |
| 75 | + style="<?php echo esc_attr( $field['style'] ); ?>" | |
| 76 | + name="<?php echo esc_attr( $field['id'] ); ?>" | |
| 77 | + id="<?php echo esc_attr( $field['id'] ); ?>" | |
| 78 | + value="<?php echo esc_attr( $field['value'] ); ?>" | |
| 79 | + placeholder="<?php echo esc_attr( $field['placeholder'] ); ?>" | |
| 80 | + <?php echo learn_press_echo_vuejs_write_on_php( $custom_attributes_str ); ?> /> | |
| 49 | 81 | <?php |
| 50 | 82 | if ( ! empty( $field['description'] ) ) { |
| 51 | 83 | echo '<p class="description">'; |
| 52 | 84 | echo '<span>' . wp_kses_post( $field['description'] ) . '</span>'; |
| @@ -68,15 +100,15 @@ | ||
| 68 | 100 | */ |
| 69 | 101 | function lp_meta_box_textarea_field( $field ) { |
| 70 | 102 | global $thepostid, $post; |
| 71 | 103 | |
| 72 | - $thepostid = empty( $thepostid ) ? $post->ID : $thepostid; | |
| 104 | + $thepostid = lp_meta_box_get_post_id(); | |
| 73 | 105 | $field['id'] = esc_attr( $field['id'] ?? '' ); |
| 74 | 106 | $field['placeholder'] = esc_attr( $field['placeholder'] ?? '' ); |
| 75 | 107 | $field['class'] = esc_attr( $field['class'] ?? 'short' ); |
| 76 | 108 | $field['style'] = esc_attr( $field['style'] ?? '' ); |
| 77 | - $value_exists = LP_Database::getInstance()->check_key_postmeta_exists( $thepostid, $field['id'] ); | |
| 78 | - $value = get_post_meta( $thepostid, $field['id'], true ); | |
| 109 | + $value_exists = $thepostid > 0 ? LP_Database::getInstance()->check_key_postmeta_exists( $thepostid, $field['id'] ) : false; | |
| 110 | + $value = $thepostid > 0 ? get_post_meta( $thepostid, $field['id'], true ) : ''; | |
| 79 | 111 | $field['value'] = esc_textarea( $value_exists ? $value : ( $field['default'] ?? '' ) ); |
| 80 | 112 | $field['desc_tip'] = esc_attr( $field['desc_tip'] ?? '' ); |
| 81 | 113 | $field['name'] = esc_attr( $field['name'] ?? $field['id'] ); |
| 82 | 114 | |
| @@ -90,16 +122,18 @@ | ||
| 90 | 122 | |
| 91 | 123 | $custom_attributes_str = implode( ' ', $custom_attributes ); |
| 92 | 124 | ?> |
| 93 | 125 | |
| 94 | - <p class="form-field <?php echo $field['id'] . '_field '; ?>"> | |
| 95 | - <label for="<?php echo $field['id']; ?>>"><?php echo wp_kses_post( $field['label'] ); ?></label> | |
| 96 | - <textarea class="<?php echo $field['class']; ?>" | |
| 97 | - style="<?php echo $field['style']; ?>" | |
| 98 | - name="<?php echo $field['name']; ?>" | |
| 99 | - id="<?php $field['id']; ?>" | |
| 100 | - placeholder="<?php echo $field['placeholder']; ?>" | |
| 101 | - rows="5" <?php echo $custom_attributes_str; ?>><?php echo $field['value']; ?></textarea> | |
| 126 | + <p class="form-field <?php echo esc_attr( $field['id'] . '_field ' ); ?>"> | |
| 127 | + <label for="<?php echo esc_attr( $field['id'] ); ?>>"> | |
| 128 | + <?php echo wp_kses_post( $field['label'] ); ?> | |
| 129 | + </label> | |
| 130 | + <textarea class="<?php echo esc_attr( $field['class'] ); ?>" | |
| 131 | + style="<?php echo esc_attr( $field['style'] ); ?>" | |
| 132 | + name="<?php echo esc_attr( $field['name'] ); ?>" | |
| 133 | + id="<?php esc_attr( $field['id'] ); ?>" | |
| 134 | + placeholder="<?php echo esc_attr( $field['placeholder'] ); ?>" | |
| 135 | + rows="5" <?php echo esc_attr( $custom_attributes_str ); ?>><?php echo wp_kses_post( $field['value'] ); ?></textarea> | |
| 102 | 136 | <?php |
| 103 | 137 | if ( ! empty( $field['description'] ) ) { |
| 104 | 138 | echo '<span class="description">' . wp_kses_post( $field['description'] ) . '</span>'; |
| 105 | 139 | |
| @@ -119,9 +153,9 @@ | ||
| 119 | 153 | */ |
| 120 | 154 | function lp_meta_box_checkbox_field( $field ) { |
| 121 | 155 | global $thepostid, $post; |
| 122 | 156 | |
| 123 | - $thepostid = empty( $thepostid ) ? $post->ID : $thepostid; | |
| 157 | + $thepostid = lp_meta_box_get_post_id(); | |
| 124 | 158 | $field['id'] = esc_attr( $field['id'] ?? '' ); |
| 125 | 159 | $field['class'] = esc_attr( $field['class'] ?? '' ); |
| 126 | 160 | $field['style'] = esc_attr( $field['style'] ?? '' ); |
| 127 | 161 | $wrapper_class = esc_attr( $field['wrapper_class'] ?? '' ); |
| @@ -144,20 +178,21 @@ | ||
| 144 | 178 | |
| 145 | 179 | $custom_attributes_str = implode( ' ', $custom_attributes ); |
| 146 | 180 | ?> |
| 147 | 181 | |
| 148 | - <div class="form-field <?php echo $field['id'] . '_field'; ?>" <?php echo $wrapper_class; ?>> | |
| 149 | - <label for="<?php echo $field['id']; ?>"><?php echo wp_kses_post( $field['label'] ); ?></label> | |
| 182 | + <div class="form-field <?php echo esc_attr( $field['id'] . '_field' . $wrapper_class ); ?>"> | |
| 183 | + <label for="<?php echo esc_attr( $field['id'] ); ?>"> | |
| 184 | + <?php echo wp_kses_post( $field['label'] ); ?> | |
| 185 | + </label> | |
| 150 | 186 | |
| 151 | 187 | <input type="checkbox" |
| 152 | - class="<?php echo $field['class']; ?>" | |
| 153 | - style="<?php echo $field['style']; ?>" | |
| 154 | - name="<?php echo $name; ?>" | |
| 155 | - id="<?php echo $field['id']; ?>" | |
| 156 | - <?php echo $checked; ?> | |
| 188 | + class="<?php echo esc_attr( $field['class'] ); ?>" | |
| 189 | + style="<?php echo esc_attr( $field['style'] ); ?>" | |
| 190 | + name="<?php echo esc_attr( $name ); ?>" | |
| 191 | + id="<?php echo esc_attr( $field['id'] ); ?>" | |
| 192 | + <?php learn_press_echo_vuejs_write_on_php( $checked ); ?> | |
| 193 | + <?php learn_press_echo_vuejs_write_on_php( $custom_attributes_str ); ?> /> | |
| 157 | 194 | |
| 158 | - <?php echo $custom_attributes_str; ?> /> | |
| 159 | - | |
| 160 | 195 | <?php |
| 161 | 196 | if ( ! empty( $field['description'] ) ) { |
| 162 | 197 | echo '<span class="description">' . wp_kses_post( $field['description'] ) . '</span>'; |
| 163 | 198 | |
| @@ -177,9 +212,9 @@ | ||
| 177 | 212 | */ |
| 178 | 213 | function lp_meta_box_select_field( $field = array() ) { |
| 179 | 214 | global $thepostid, $post; |
| 180 | 215 | |
| 181 | - $thepostid = empty( $thepostid ) ? $post->ID : $thepostid; | |
| 216 | + $thepostid = lp_meta_box_get_post_id(); | |
| 182 | 217 | $default = ( ! get_post_meta( |
| 183 | 218 | $thepostid, |
| 184 | 219 | $field['id'], |
| 185 | 220 | true |
| @@ -207,12 +242,12 @@ | ||
| 207 | 242 | 'for' => $field['id'], |
| 208 | 243 | ); |
| 209 | 244 | |
| 210 | 245 | $field_attributes = (array) $field['custom_attributes']; |
| 211 | - $field_attributes['style'] = $field['style']; | |
| 212 | - $field_attributes['id'] = $field['id']; | |
| 246 | + $field_attributes['style'] = $field['style'] ?? ''; | |
| 247 | + $field_attributes['id'] = $field['id'] ?? ''; | |
| 213 | 248 | $field_attributes['name'] = $field['multiple'] ? $field['name'] . '[]' : $field['name']; |
| 214 | - $field_attributes['class'] = $field['class']; | |
| 249 | + $field_attributes['class'] = $field['class'] ?? ''; | |
| 215 | 250 | |
| 216 | 251 | if ( $field['multiple'] ) { |
| 217 | 252 | $field['wrapper_class'] = 'lp-select-2'; |
| 218 | 253 | $field_attributes['multiple'] = true; |
| @@ -221,9 +256,9 @@ | ||
| 221 | 256 | $tooltip = ! empty( $field['description'] ) && false !== $field['desc_tip'] ? $field['description'] : ''; |
| 222 | 257 | $description = ! empty( $field['description'] ) && false === $field['desc_tip'] ? $field['description'] : ''; |
| 223 | 258 | ?> |
| 224 | 259 | |
| 225 | - <p class="form-field <?php echo esc_attr( $field['id'] ) . '_field ' . esc_attr( $field['wrapper_class'] ); ?>"> | |
| 260 | + <p class="form-field <?php echo esc_attr( $field['id'] . '_field ' . $field['wrapper_class'] ); ?>"> | |
| 226 | 261 | <label for="<?php echo esc_attr( $field['id'] ); ?>"><?php echo wp_kses_post( $field['label'] ); ?></label> |
| 227 | 262 | <select <?php echo lp_implode_html_attributes( $field_attributes ); ?>> |
| 228 | 263 | <?php |
| 229 | 264 | foreach ( $field['options'] as $key => $value ) { |
| @@ -251,12 +286,12 @@ | ||
| 251 | 286 | */ |
| 252 | 287 | function lp_meta_box_radio_field( $field ) { |
| 253 | 288 | global $thepostid, $post; |
| 254 | 289 | |
| 255 | - $thepostid = empty( $thepostid ) ? $post->ID : $thepostid; | |
| 256 | - $field['class'] = isset( $field['class'] ) ? $field['class'] : 'select'; | |
| 257 | - $field['style'] = isset( $field['style'] ) ? $field['style'] : ''; | |
| 258 | - $field['wrapper_class'] = isset( $field['wrapper_class'] ) ? $field['wrapper_class'] : ''; | |
| 290 | + $thepostid = lp_meta_box_get_post_id(); | |
| 291 | + $field['class'] = $field['class'] ?? 'select'; | |
| 292 | + $field['style'] = $field['style'] ?? ''; | |
| 293 | + $field['wrapper_class'] = $field['wrapper_class'] ?? ''; | |
| 259 | 294 | $field['default'] = ( ! get_post_meta( |
| 260 | 295 | $thepostid, |
| 261 | 296 | $field['id'], |
| 262 | 297 | true |
| @@ -264,13 +299,13 @@ | ||
| 264 | 299 | $thepostid, |
| 265 | 300 | $field['id'], |
| 266 | 301 | true |
| 267 | 302 | ); |
| 268 | - $field['value'] = isset( $field['value'] ) ? $field['value'] : $field['default']; | |
| 269 | - $field['name'] = isset( $field['name'] ) ? $field['name'] : $field['id']; | |
| 270 | - $field['desc_tip'] = isset( $field['desc_tip'] ) ? $field['desc_tip'] : false; | |
| 303 | + $field['value'] = $field['value'] ?? $field['default']; | |
| 304 | + $field['name'] = $field['name'] ?? $field['id']; | |
| 305 | + $field['desc_tip'] = $field['desc_tip'] ?? false; | |
| 271 | 306 | |
| 272 | - echo '<fieldset class="form-field ' . esc_attr( $field['id'] ) . '_field ' . esc_attr( $field['wrapper_class'] ) . '"><h4>' . wp_kses_post( $field['label'] ) . '</h4>'; | |
| 307 | + echo '<fieldset class="form-field ' . esc_attr( $field['id'] . '_field ' . $field['wrapper_class'] ) . '"><h4>' . wp_kses_post( $field['label'] ) . '</h4>'; | |
| 273 | 308 | |
| 274 | 309 | if ( ! empty( $field['description'] ) && false !== $field['desc_tip'] ) { |
| 275 | 310 | learn_press_quick_tip( $field['description'] ); |
| 276 | 311 | } |
| @@ -299,9 +334,9 @@ | ||
| 299 | 334 | |
| 300 | 335 | function lp_meta_box_file_input_field( $field ) { |
| 301 | 336 | global $thepostid, $post; |
| 302 | 337 | |
| 303 | - $thepostid = empty( $thepostid ) ? $post->ID : $thepostid; | |
| 338 | + $thepostid = lp_meta_box_get_post_id(); | |
| 304 | 339 | $field['class'] = isset( $field['class'] ) ? $field['class'] : 'short'; |
| 305 | 340 | $field['style'] = isset( $field['style'] ) ? $field['style'] : ''; |
| 306 | 341 | $field['wrapper_class'] = isset( $field['wrapper_class'] ) ? $field['wrapper_class'] : ''; |
| 307 | 342 | $field['default'] = ( ! get_post_meta( |
| @@ -327,9 +362,9 @@ | ||
| 327 | 362 | $custom_attributes[] = esc_attr( $attribute ) . '="' . esc_attr( $custom_attribute ) . '"'; |
| 328 | 363 | } |
| 329 | 364 | } |
| 330 | 365 | |
| 331 | - echo '<div class="form-field ' . esc_attr( $field['id'] ) . '_field ' . esc_attr( $field['wrapper_class'] ) . '"> | |
| 366 | + echo '<div class="form-field ' . esc_attr( $field['id'] . '_field ' . $field['wrapper_class'] ) . '"> | |
| 332 | 367 | <label for="' . esc_attr( $field['id'] ) . '">' . wp_kses_post( $field['label'] ) . '</label>'; |
| 333 | 368 | |
| 334 | 369 | echo '<div id="' . esc_attr( $field['id'] ) . '" class="lp-meta-box__file ' . esc_attr( $field['class'] ) . '" data-mime="' . $field['mime_type'] . '" data-multil="' . $field['multil'] . '" style="' . esc_attr( $field['style'] ) . '" ' . implode( |
| 335 | 370 | ' ', |
| @@ -386,13 +421,13 @@ | ||
| 386 | 421 | */ |
| 387 | 422 | function lp_meta_box_duration_field( $field ) { |
| 388 | 423 | global $thepostid, $post; |
| 389 | 424 | |
| 390 | - $thepostid = empty( $thepostid ) ? $post->ID : $thepostid; | |
| 391 | - $field['placeholder'] = isset( $field['placeholder'] ) ? $field['placeholder'] : ''; | |
| 392 | - $field['class'] = isset( $field['class'] ) ? $field['class'] : 'short'; | |
| 393 | - $field['style'] = isset( $field['style'] ) ? $field['style'] : ''; | |
| 394 | - $field['wrapper_class'] = isset( $field['wrapper_class'] ) ? $field['wrapper_class'] : ''; | |
| 425 | + $thepostid = lp_meta_box_get_post_id(); | |
| 426 | + $field['placeholder'] = $field['placeholder'] ?? ''; | |
| 427 | + $field['class'] = $field['class'] ?? 'short'; | |
| 428 | + $field['style'] = $field['style'] ?? ''; | |
| 429 | + $field['wrapper_class'] = $field['wrapper_class'] ?? ''; | |
| 395 | 430 | $field['default'] = ( ! get_post_meta( |
| 396 | 431 | $thepostid, |
| 397 | 432 | $field['id'], |
| 398 | 433 | true |
| @@ -400,10 +435,10 @@ | ||
| 400 | 435 | $thepostid, |
| 401 | 436 | $field['id'], |
| 402 | 437 | true |
| 403 | 438 | ); |
| 404 | - $field['value'] = isset( $field['value'] ) ? $field['value'] : $field['default']; | |
| 405 | - $field['name'] = isset( $field['name'] ) ? $field['name'] : $field['id']; | |
| 439 | + $field['value'] = $field['value'] ?? $field['default']; | |
| 440 | + $field['name'] = $field['name'] ?? $field['id']; | |
| 406 | 441 | $data_type = empty( $field['data_type'] ) ? '' : $field['data_type']; |
| 407 | 442 | $duration = learn_press_get_course_duration_support(); |
| 408 | 443 | |
| 409 | 444 | $duration_keys = array_keys( $duration ); |
| @@ -430,9 +465,9 @@ | ||
| 430 | 465 | foreach ( $duration as $k => $v ) { |
| 431 | 466 | $html_option .= sprintf( '<option value="%s" %s>%s</option>', $k, selected( $k, $a2, false ), $v ); |
| 432 | 467 | } |
| 433 | 468 | |
| 434 | - echo '<p class="lp-meta-box__duration form-field ' . esc_attr( $field['id'] ) . '_field ' . esc_attr( $field['wrapper_class'] ) . '"> | |
| 469 | + echo '<p class="lp-meta-box__duration form-field ' . esc_attr( $field['id'] . '_field ' . $field['wrapper_class'] ) . '"> | |
| 435 | 470 | <label for="' . esc_attr( $field['id'] ) . '">' . wp_kses_post( $field['label'] ) . '</label>'; |
| 436 | 471 | |
| 437 | 472 | echo '<input type="number" class="' . esc_attr( $field['class'] ) . '" style="' . esc_attr( $field['style'] ) . '" name="' . esc_attr( $field['name'] ) . '[]" id="' . esc_attr( $field['id'] ) . '" value="' . esc_attr( $a1 ) . '" placeholder="' . esc_attr( $field['placeholder'] ) . '" ' . implode( |
| 438 | 473 | ' ', |
| @@ -464,9 +499,9 @@ | ||
| 464 | 499 | function lp_metabox_custom_fields( $field, $values, $key ) { |
| 465 | 500 | ?> |
| 466 | 501 | <tr> |
| 467 | 502 | <td class="sort"> |
| 468 | - <input class="count" type="hidden" value="<?php echo $key; ?>" name="<?php echo esc_attr( $field['id'] ) . '[' . $key . ']' . '[sort]'; ?>"> | |
| 503 | + <input class="count" type="hidden" value="<?php echo esc_attr( $key ); ?>" name="<?php echo esc_attr( $field['id'] ) . '[' . $key . ']' . '[sort]'; ?>"> | |
| 469 | 504 | <input type="hidden" value="<?php echo ! empty( $values['id'] ) ? $values['id'] : wp_rand( 1, 10000 ) . $key; ?>" name="<?php echo esc_attr( $field['id'] ) . '[' . $key . ']' . '[id]'; ?>"> |
| 470 | 505 | </td> |
| 471 | 506 | <?php |
| 472 | 507 | if ( $field['options'] ) { |
| @@ -487,9 +522,9 @@ | ||
| 487 | 522 | case 'url': |
| 488 | 523 | case 'tel': |
| 489 | 524 | ?> |
| 490 | 525 | <td> |
| 491 | - <input name="<?php echo esc_attr( $name ); ?>" type="<?php echo $val['type']; ?>" | |
| 526 | + <input name="<?php echo esc_attr( $name ); ?>" type="<?php echo esc_attr( $val['type'] ); ?>" | |
| 492 | 527 | class="input-text" |
| 493 | 528 | placeholder="<?php echo isset( $val['placeholder'] ) ? esc_attr( $val['placeholder'] ) : ''; ?>" |
| 494 | 529 | value="<?php echo ! empty( $values[ $cfk ] ) ? esc_attr( $values[ $cfk ] ) : ''; ?>"> |
| 495 | 530 | </td> |
| @@ -511,9 +546,9 @@ | ||
| 511 | 546 | $values[ $cfk ], |
| 512 | 547 | (string) $cfks |
| 513 | 548 | ) : ''; |
| 514 | 549 | ?> |
| 515 | - ><?php echo $cfselect; ?></option> | |
| 550 | + ><?php echo wp_kses_post( $cfselect ); ?></option> | |
| 516 | 551 | <?php |
| 517 | 552 | } |
| 518 | 553 | } |
| 519 | 554 | ?> |