PluginProbe
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar / 3.3.3
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar v3.3.3
3.3.3 3.3.2 3.3.1 3.3.0 3.2.14 3.2.13 3.2.12 3.2.11 3.2.10 3.2.9 3.2.8 3.2.7 trunk 0.2.5.5 0.2.5.6 0.2.5.7 1.0.0 1.0.1 1.0.2 1.0.3 1.1.0 1.1.1 1.1.2 1.1.3 1.1.4 All 158 releases
← All changes | blocks/style-handler/style-handler.php +15 -8 3.2.11 → 3.3.3 View file →
@@ -110,18 +110,23 @@
110 110 * @retun void
111 111 * @since 1.0.2
112 112 */
113 113 public function write_block_css() {
114 - if ( ! isset( $_POST['nonce'] ) || ! wp_verify_nonce( $_POST['nonce'], 'nx_style_handler_nonce' ) || ! current_user_can( 'manage_options' ) ) {
114 + if ( ! isset( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_POST['nonce'] ) ), 'nx_style_handler_nonce' ) || ! current_user_can( 'manage_options' ) ) {
115 115 echo 'Invalid request';
116 116 wp_die();
117 117 }
118 118
119 - $block_styles = (array) json_decode( stripslashes( $_POST['data'] ) );
119 + // The payload is a JSON blob of block styles, so it cannot be run through a
120 + // scalar sanitiser without destroying it. It is decoded structurally below and
121 + // this endpoint is already gated on a nonce plus manage_options above.
122 + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
123 + $block_styles = isset( $_POST['data'] ) ? (array) json_decode( wp_unslash( $_POST['data'] ) ) : array();
120 124
121 - if ( isset( $_POST['editorType'] ) && $_POST['editorType'] === 'edit-site' ) {
125 + $editor_type = isset( $_POST['editorType'] ) ? sanitize_key( wp_unslash( $_POST['editorType'] ) ) : '';
126 + if ( $editor_type === 'edit-site' ) {
122 127 $upload_dir = wp_upload_dir()['basedir'] . '/nx-style/';
123 - $editSiteCssPath = $upload_dir . 'nx-style-' . $_POST['editorType'] . '.min.css';
128 + $editSiteCssPath = $upload_dir . 'nx-style-' . $editor_type . '.min.css';
124 129 if ( file_exists( $editSiteCssPath ) ) {
125 130 $existingCss = file_get_contents( $editSiteCssPath );
126 131 $pattern = '~\/\*(.*?)\*\/~';
127 132 preg_match_all( $pattern, $existingCss, $result, PREG_PATTERN_ORDER );
@@ -147,9 +152,9 @@
147 152
148 153 if ( ! empty( $css = $this->build_css( $finalCSSArray ) ) ) {
149 154 $upload_dir = wp_upload_dir()['basedir'] . '/nx-style/';
150 155 if ( ! file_exists( $upload_dir ) ) {
151 - mkdir( $upload_dir );
156 + wp_mkdir_p( $upload_dir );
152 157 }
153 158
154 159 file_put_contents( $editSiteCssPath, $css );
155 160 }
@@ -156,9 +161,9 @@
156 161 } else {
157 162 if ( ! empty( $css = $this->build_css( $block_styles ) ) ) {
158 163 $upload_dir = wp_upload_dir()['basedir'] . '/nx-style/';
159 164 if ( ! file_exists( $upload_dir ) ) {
160 - mkdir( $upload_dir );
165 + wp_mkdir_p( $upload_dir );
161 166 }
162 167
163 168 file_put_contents( $editSiteCssPath, $css );
164 169 }
@@ -166,11 +171,12 @@
166 171 } else {
167 172 if ( ! empty( $css = $this->build_css( $block_styles ) ) ) {
168 173 $upload_dir = wp_upload_dir()['basedir'] . '/nx-style/';
169 174 if ( ! file_exists( $upload_dir ) ) {
170 - mkdir( $upload_dir );
175 + wp_mkdir_p( $upload_dir );
171 176 }
172 - file_put_contents( $upload_dir . 'nx-style-' . abs( $_POST['id'] ) . '.min.css', $css );
177 + $style_id = isset( $_POST['id'] ) ? absint( wp_unslash( $_POST['id'] ) ) : 0;
178 + file_put_contents( $upload_dir . 'nx-style-' . $style_id . '.min.css', $css );
173 179 }
174 180 }
175 181
176 182 wp_die();
@@ -206,8 +212,9 @@
206 212
207 213 if ( file_exists( $upload_dir['basedir'] . '/nx-style/nx-style-' . $post->ID . '.min.css' ) ) {
208 214 wp_enqueue_style( 'nx-block-style-' . $post->ID, $upload_dir['baseurl'] . '/nx-style/nx-style-' . $post->ID . '.min.css', [], substr( md5( microtime( true ) ), 0, 10 ) );
209 215 } elseif ( function_exists( 'icl_object_id' ) ) {
216 + // phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedHooknameFound -- Reviewed for the NotificationX codebase: acceptable in this context.
210 217 $default_language = apply_filters( 'wpml_default_language', null );
211 218 $english_version = icl_object_id( $post->ID, 'post', false, $default_language );
212 219 if ( file_exists( $upload_dir['basedir'] . '/nx-style/nx-style-' . $english_version . '.min.css' ) ) {
213 220 wp_enqueue_style( 'nx-block-style-' . $english_version, $upload_dir['baseurl'] . '/nx-style/nx-style-' . $english_version . '.min.css', [], substr( md5( microtime( true ) ), 0, 10 ) );