| @@ -18,12 +18,12 @@ | ||
| 18 | 18 | * |
| 19 | 19 | * @return mixed |
| 20 | 20 | */ |
| 21 | 21 | public static function maybe_unserialize( $string ) { |
| 22 | - if ( is_string( $string ) ) { | |
| 23 | - | |
| 24 | - $unserialized = maybe_unserialize( $string ); | |
| 25 | - if ( ! $unserialized && strlen( $string ) ) { | |
| 22 | + if ( is_string( $string ) && is_serialized( $string ) ) { | |
| 23 | + $string = trim( $string ); | |
| 24 | + $unserialized = @unserialize( $string, array( 'allowed_classes' => false ) ); | |
| 25 | + if ( false === $unserialized && 'b:0;' !== $string ) { | |
| 26 | 26 | $string = preg_replace_callback( |
| 27 | 27 | '!s:(\d+):"(.*?)";!s', |
| 28 | 28 | array( __CLASS__, '_unserialize_replace_callback' ), |
| 29 | 29 | $string |
| @@ -28,9 +28,9 @@ | ||
| 28 | 28 | array( __CLASS__, '_unserialize_replace_callback' ), |
| 29 | 29 | $string |
| 30 | 30 | ); |
| 31 | 31 | |
| 32 | - $unserialized = maybe_unserialize( $string ); | |
| 32 | + $unserialized = @unserialize( $string, array( 'allowed_classes' => false ) ); | |
| 33 | 33 | } |
| 34 | 34 | |
| 35 | 35 | $string = $unserialized; |
| 36 | 36 | } |
| @@ -354,8 +354,11 @@ | ||
| 354 | 354 | break; |
| 355 | 355 | case 'float': |
| 356 | 356 | $value = (float) $value; |
| 357 | 357 | break; |
| 358 | + case 'email': | |
| 359 | + $value = sanitize_email( $value ); | |
| 360 | + break; | |
| 358 | 361 | default: |
| 359 | 362 | if ( is_callable( $type_content ) ) { |
| 360 | 363 | $value = call_user_func( $type_content, $value ); |
| 361 | 364 | } else { |
| @@ -533,19 +536,25 @@ | ||
| 533 | 536 | * @param array $data |
| 534 | 537 | * @param array $tag_args as ['type' => 'text/javascript', 'id' => ''] |
| 535 | 538 | * |
| 536 | 539 | * @return void |
| 537 | - * @version 1.0.1 | |
| 540 | + * @version 1.0.2 | |
| 538 | 541 | * @since 4.2.5.5 |
| 539 | 542 | */ |
| 540 | 543 | public static function print_inline_script_tag( string $name_variable_script, array $data, array $tag_args = [] ) { |
| 541 | - foreach ( $data as $key => $value ) { | |
| 544 | + /** | |
| 545 | + * Comment block code reason by security | |
| 546 | + * wp_json_encode() already produces a valid JavaScript string, | |
| 547 | + * and there is no reason to decode HTML entities inside data that will be re-inserted with insertAdjacentHTML | |
| 548 | + * @comment since 4.4.8 | |
| 549 | + */ | |
| 550 | + /*foreach ( $data as $key => $value ) { | |
| 542 | 551 | if ( ! is_scalar( $value ) ) { |
| 543 | 552 | continue; |
| 544 | 553 | } |
| 545 | 554 | |
| 546 | 555 | $data[ $key ] = html_entity_decode( (string) $value, ENT_QUOTES, 'UTF-8' ); |
| 547 | - } | |
| 556 | + }*/ | |
| 548 | 557 | |
| 549 | 558 | $data_json = wp_json_encode( $data ); |
| 550 | 559 | $script = ''; |
| 551 | 560 | if ( ! empty( $name_variable_script ) ) { |