| @@ -9,8 +9,11 @@ | ||
| 9 | 9 | |
| 10 | 10 | /** |
| 11 | 11 | * Prevent loading this file directly |
| 12 | 12 | */ |
| 13 | + | |
| 14 | +use LearnPress\Helpers\Template; | |
| 15 | + | |
| 13 | 16 | defined( 'ABSPATH' ) || exit(); |
| 14 | 17 | |
| 15 | 18 | if ( ! class_exists( 'LP_Question' ) ) { |
| 16 | 19 | |
| @@ -326,9 +329,11 @@ | ||
| 326 | 329 | /** |
| 327 | 330 | * @return mixed |
| 328 | 331 | */ |
| 329 | 332 | public function get_explanation() { |
| 330 | - return apply_filters( 'learn-press/question/explanation', do_shortcode( $this->get_data( 'explanation' ) ), $this->get_id() ); | |
| 333 | + $explanation = apply_filters( 'learn-press/question/explanation', do_shortcode( $this->get_data( 'explanation' ) ), $this->get_id() ); | |
| 334 | + | |
| 335 | + return Template::sanitize_html_content( (string) $explanation ); | |
| 331 | 336 | } |
| 332 | 337 | |
| 333 | 338 | /** |
| 334 | 339 | * @param string $hint |
| @@ -340,9 +345,11 @@ | ||
| 340 | 345 | /** |
| 341 | 346 | * @return mixed |
| 342 | 347 | */ |
| 343 | 348 | public function get_hint() { |
| 344 | - return apply_filters( 'learn-press/question/hint', do_shortcode( $this->get_data( 'hint' ) ), $this->get_id() ); | |
| 349 | + $hint = apply_filters( 'learn-press/question/hint', do_shortcode( $this->get_data( 'hint' ) ), $this->get_id() ); | |
| 350 | + | |
| 351 | + return Template::sanitize_html_content( (string) $hint ); | |
| 345 | 352 | } |
| 346 | 353 | |
| 347 | 354 | /** |
| 348 | 355 | * Get all type of questions |
| @@ -517,23 +524,23 @@ | ||
| 517 | 524 | $query = " |
| 518 | 525 | UPDATE {$wpdb->learnpress_question_answers} |
| 519 | 526 | SET `order` = CASE |
| 520 | 527 | "; |
| 521 | - for ( $order = 0, $n = sizeof( $orders ); $order < $n; $order ++ ) { | |
| 522 | - $found_answer = false; | |
| 523 | - foreach ( $answers as $answer ) { | |
| 524 | - if ( $answer->value == $orders[ $order ]['value'] && $answer->name == $orders[ $order ]['text'] ) { | |
| 525 | - $found_answer = $answer; | |
| 526 | - break; | |
| 527 | - } | |
| 528 | + for ( $order = 0, $n = sizeof( $orders ); $order < $n; $order ++ ) { | |
| 529 | + $found_answer = false; | |
| 530 | + foreach ( $answers as $answer ) { | |
| 531 | + if ( $answer->value == $orders[ $order ]['value'] && $answer->name == $orders[ $order ]['text'] ) { | |
| 532 | + $found_answer = $answer; | |
| 533 | + break; | |
| 528 | 534 | } |
| 529 | - if ( $found_answer === false ) { | |
| 530 | - continue; | |
| 531 | - } | |
| 532 | - $query .= $wpdb->prepare( 'WHEN question_answer_id = %d THEN %d', $found_answer->question_answer_id, $order + 1 ) . "\n"; | |
| 533 | 535 | } |
| 534 | - $query .= sprintf( 'ELSE `order` END WHERE question_id = %d', $this->get_id() ); | |
| 535 | - $wpdb->query( $query ); | |
| 536 | + if ( $found_answer === false ) { | |
| 537 | + continue; | |
| 538 | + } | |
| 539 | + $query .= $wpdb->prepare( 'WHEN question_answer_id = %d THEN %d', $found_answer->question_answer_id, $order + 1 ) . "\n"; | |
| 540 | + } | |
| 541 | + $query .= sprintf( 'ELSE `order` END WHERE question_id = %d', $this->get_id() ); | |
| 542 | + $wpdb->query( $query ); | |
| 536 | 543 | }*/ |
| 537 | 544 | } |
| 538 | 545 | |
| 539 | 546 | /** |