PluginProbe
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses / 4.4.10
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses v4.4.10
4.4.10 4.4.9.1 4.4.9 4.4.8 4.4.7 4.4.6 4.4.5 4.4.4 4.4.3 4.4.2 4.4.1 4.4.0 4.3.9.1 4.3.9 4.3.8 4.3.7 4.1.6.9 4.1.6.9.1 4.1.6.9.2 4.1.6.9.3 4.1.6.9.4 4.1.7 4.1.7.1 4.1.7.2 4.1.7.3 All 142 releases
← All changes | inc/class-lp-helper.php +41 -8 4.4.4 → 4.4.10 View file →
@@ -18,12 +18,12 @@
18 18 *
19 19 * @return mixed
20 20 */
21 21 public static function maybe_unserialize( $string ) {
22 - if ( is_string( $string ) ) {
23 -
24 - $unserialized = maybe_unserialize( $string );
25 - if ( ! $unserialized && strlen( $string ) ) {
22 + if ( is_string( $string ) && is_serialized( $string ) ) {
23 + $string = trim( $string );
24 + $unserialized = @unserialize( $string, array( 'allowed_classes' => false ) );
25 + if ( false === $unserialized && 'b:0;' !== $string ) {
26 26 $string = preg_replace_callback(
27 27 '!s:(\d+):"(.*?)";!s',
28 28 array( __CLASS__, '_unserialize_replace_callback' ),
29 29 $string
@@ -28,9 +28,9 @@
28 28 array( __CLASS__, '_unserialize_replace_callback' ),
29 29 $string
30 30 );
31 31
32 - $unserialized = maybe_unserialize( $string );
32 + $unserialized = @unserialize( $string, array( 'allowed_classes' => false ) );
33 33 }
34 34
35 35 $string = $unserialized;
36 36 }
@@ -230,8 +230,32 @@
230 230 public static function create_page( array $args, string $key_option ) {
231 231 $page_id = 0;
232 232
233 233 try {
234 + /**
235 + * Whitelist of allowed page option keys for security.
236 + * Prevents arbitrary options from being set via the key_option parameter.
237 + */
238 + $key_pages_allow = apply_filters(
239 + 'learn-press/pages/create-allow',
240 + array(
241 + 'learn_press_checkout_page_id',
242 + 'learn_press_profile_page_id',
243 + 'learn_press_courses_page_id',
244 + 'learn_press_instructors_page_id',
245 + 'learn_press_single_instructor_page_id',
246 + 'learn_press_become_a_teacher_page_id',
247 + 'learn_press_term_conditions_page_id',
248 + 'learn_press_exams_page_id', // Must update Addon Exam v4.0.0
249 + 'learn_press_collections_page_id', // Must update Addon Collections v4.0.5
250 + 'learn_press_packages_page_id', // Must update Addon UpSell v4.0.9
251 + )
252 + );
253 +
254 + if ( ! in_array( $key_option, $key_pages_allow ) ) {
255 + throw new Exception( __( 'Invalid key page', 'learnpress' ) );
256 + }
257 +
234 258 if ( ! isset( $args['post_title'] ) ) {
235 259 throw new Exception( __( 'Missing post title', 'learnpress' ) );
236 260 }
237 261
@@ -330,8 +354,11 @@
330 354 break;
331 355 case 'float':
332 356 $value = (float) $value;
333 357 break;
358 + case 'email':
359 + $value = sanitize_email( $value );
360 + break;
334 361 default:
335 362 if ( is_callable( $type_content ) ) {
336 363 $value = call_user_func( $type_content, $value );
337 364 } else {
@@ -509,19 +536,25 @@
509 536 * @param array $data
510 537 * @param array $tag_args as ['type' => 'text/javascript', 'id' => '']
511 538 *
512 539 * @return void
513 - * @version 1.0.1
540 + * @version 1.0.2
514 541 * @since 4.2.5.5
515 542 */
516 543 public static function print_inline_script_tag( string $name_variable_script, array $data, array $tag_args = [] ) {
517 - foreach ( $data as $key => $value ) {
544 + /**
545 + * Comment block code reason by security
546 + * wp_json_encode() already produces a valid JavaScript string,
547 + * and there is no reason to decode HTML entities inside data that will be re-inserted with insertAdjacentHTML
548 + * @comment since 4.4.8
549 + */
550 + /*foreach ( $data as $key => $value ) {
518 551 if ( ! is_scalar( $value ) ) {
519 552 continue;
520 553 }
521 554
522 555 $data[ $key ] = html_entity_decode( (string) $value, ENT_QUOTES, 'UTF-8' );
523 - }
556 + }*/
524 557
525 558 $data_json = wp_json_encode( $data );
526 559 $script = '';
527 560 if ( ! empty( $name_variable_script ) ) {