| @@ -18,12 +18,12 @@ | ||
| 18 | 18 | * |
| 19 | 19 | * @return mixed |
| 20 | 20 | */ |
| 21 | 21 | public static function maybe_unserialize( $string ) { |
| 22 | - if ( is_string( $string ) ) { | |
| 23 | - | |
| 24 | - $unserialized = maybe_unserialize( $string ); | |
| 25 | - if ( ! $unserialized && strlen( $string ) ) { | |
| 22 | + if ( is_string( $string ) && is_serialized( $string ) ) { | |
| 23 | + $string = trim( $string ); | |
| 24 | + $unserialized = @unserialize( $string, array( 'allowed_classes' => false ) ); | |
| 25 | + if ( false === $unserialized && 'b:0;' !== $string ) { | |
| 26 | 26 | $string = preg_replace_callback( |
| 27 | 27 | '!s:(\d+):"(.*?)";!s', |
| 28 | 28 | array( __CLASS__, '_unserialize_replace_callback' ), |
| 29 | 29 | $string |
| @@ -28,9 +28,9 @@ | ||
| 28 | 28 | array( __CLASS__, '_unserialize_replace_callback' ), |
| 29 | 29 | $string |
| 30 | 30 | ); |
| 31 | 31 | |
| 32 | - $unserialized = maybe_unserialize( $string ); | |
| 32 | + $unserialized = @unserialize( $string, array( 'allowed_classes' => false ) ); | |
| 33 | 33 | } |
| 34 | 34 | |
| 35 | 35 | $string = $unserialized; |
| 36 | 36 | } |
| @@ -230,8 +230,32 @@ | ||
| 230 | 230 | public static function create_page( array $args, string $key_option ) { |
| 231 | 231 | $page_id = 0; |
| 232 | 232 | |
| 233 | 233 | try { |
| 234 | + /** | |
| 235 | + * Whitelist of allowed page option keys for security. | |
| 236 | + * Prevents arbitrary options from being set via the key_option parameter. | |
| 237 | + */ | |
| 238 | + $key_pages_allow = apply_filters( | |
| 239 | + 'learn-press/pages/create-allow', | |
| 240 | + array( | |
| 241 | + 'learn_press_checkout_page_id', | |
| 242 | + 'learn_press_profile_page_id', | |
| 243 | + 'learn_press_courses_page_id', | |
| 244 | + 'learn_press_instructors_page_id', | |
| 245 | + 'learn_press_single_instructor_page_id', | |
| 246 | + 'learn_press_become_a_teacher_page_id', | |
| 247 | + 'learn_press_term_conditions_page_id', | |
| 248 | + 'learn_press_exams_page_id', // Must update Addon Exam v4.0.0 | |
| 249 | + 'learn_press_collections_page_id', // Must update Addon Collections v4.0.5 | |
| 250 | + 'learn_press_packages_page_id', // Must update Addon UpSell v4.0.9 | |
| 251 | + ) | |
| 252 | + ); | |
| 253 | + | |
| 254 | + if ( ! in_array( $key_option, $key_pages_allow ) ) { | |
| 255 | + throw new Exception( __( 'Invalid key page', 'learnpress' ) ); | |
| 256 | + } | |
| 257 | + | |
| 234 | 258 | if ( ! isset( $args['post_title'] ) ) { |
| 235 | 259 | throw new Exception( __( 'Missing post title', 'learnpress' ) ); |
| 236 | 260 | } |
| 237 | 261 | |
| @@ -330,8 +354,11 @@ | ||
| 330 | 354 | break; |
| 331 | 355 | case 'float': |
| 332 | 356 | $value = (float) $value; |
| 333 | 357 | break; |
| 358 | + case 'email': | |
| 359 | + $value = sanitize_email( $value ); | |
| 360 | + break; | |
| 334 | 361 | default: |
| 335 | 362 | if ( is_callable( $type_content ) ) { |
| 336 | 363 | $value = call_user_func( $type_content, $value ); |
| 337 | 364 | } else { |
| @@ -509,19 +536,25 @@ | ||
| 509 | 536 | * @param array $data |
| 510 | 537 | * @param array $tag_args as ['type' => 'text/javascript', 'id' => ''] |
| 511 | 538 | * |
| 512 | 539 | * @return void |
| 513 | - * @version 1.0.1 | |
| 540 | + * @version 1.0.2 | |
| 514 | 541 | * @since 4.2.5.5 |
| 515 | 542 | */ |
| 516 | 543 | public static function print_inline_script_tag( string $name_variable_script, array $data, array $tag_args = [] ) { |
| 517 | - foreach ( $data as $key => $value ) { | |
| 544 | + /** | |
| 545 | + * Comment block code reason by security | |
| 546 | + * wp_json_encode() already produces a valid JavaScript string, | |
| 547 | + * and there is no reason to decode HTML entities inside data that will be re-inserted with insertAdjacentHTML | |
| 548 | + * @comment since 4.4.8 | |
| 549 | + */ | |
| 550 | + /*foreach ( $data as $key => $value ) { | |
| 518 | 551 | if ( ! is_scalar( $value ) ) { |
| 519 | 552 | continue; |
| 520 | 553 | } |
| 521 | 554 | |
| 522 | 555 | $data[ $key ] = html_entity_decode( (string) $value, ENT_QUOTES, 'UTF-8' ); |
| 523 | - } | |
| 556 | + }*/ | |
| 524 | 557 | |
| 525 | 558 | $data_json = wp_json_encode( $data ); |
| 526 | 559 | $script = ''; |
| 527 | 560 | if ( ! empty( $name_variable_script ) ) { |