PluginProbe
Patchstack – WordPress & Plugins Security / 2.1.22
Patchstack – WordPress & Plugins Security v2.1.22
2.3.7 trunk 2.1.0 2.1.1 2.1.10 2.1.11 2.1.12 2.1.13 2.1.14 2.1.15 2.1.16 2.1.17 2.1.18 2.1.19 2.1.2 2.1.20 2.1.21 2.1.22 2.1.23 2.1.24 2.1.25 2.1.3 2.1.4 2.1.5 2.1.6 All 49 releases
patchstack / includes / admin / ajax.php

ajax.php in Patchstack – WordPress & Plugins Security 2.1.22, at includes/admin/ajax.php

191 lines 5.9 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 // Do not allow the file to be called directly.
4 if ( ! defined( 'ABSPATH' ) ) {
5 exit;
6 }
7
8 /**
9 * This class is used for any admin AJAX interactions.
10 */
11 class P_Admin_Ajax extends P_Core {
12
13 /**
14 * Add the actions required for AJAX interactions.
15 *
16 * @param Patchstack $core
17 * @return void
18 */
19 public function __construct( $core ) {
20 parent::__construct( $core );
21 if ( isset( $_POST['PatchstackNonce'] ) && current_user_can( 'manage_options' ) && wp_verify_nonce( $_POST['PatchstackNonce'], 'patchstack-nonce' ) ) {
22 // Log tables actions.
23 add_action( 'wp_ajax_patchstack_users_log_table', array( $this, 'users_log_table' ) );
24 add_action( 'wp_ajax_patchstack_firewall_log_table', array( $this, 'firewall_log_table' ) );
25
26 // License related actions.
27 add_action( 'wp_ajax_patchstack_activate_license', array( $this, 'activate_license' ) );
28
29 // Hide login related actions.
30 add_action( 'wp_ajax_patchstack_send_new_url_email', array( $this, 'send_new_url_email' ) );
31 }
32 }
33
34 /**
35 * Firewall logs pagination.
36 *
37 * @return array
38 */
39 public function firewall_log_table() {
40 if ( ! isset( $_POST['start'], $_POST['length'] ) || !ctype_digit( $_POST['start'] ) || !ctype_digit( $_POST['length'] ) ) {
41 exit;
42 }
43
44 // Pull all entries, given parameters.
45 global $wpdb;
46 $entries = $wpdb->get_results(
47 $wpdb->prepare(
48 "SELECT a.id, a.ip, a.flag, a.method, a.log_date, case when a.referer IS NULL or a.referer = '' then a.request_uri else a.referer end as referer, a.fid, b.description
49 FROM " . $wpdb->prefix . 'patchstack_firewall_log AS a
50 LEFT JOIN ' . $wpdb->prefix . 'patchstack_logic AS b ON b.id = a.fid
51 ORDER BY a.id DESC
52 LIMIT %d, %d
53 ',
54 array( wp_filter_nohtml_kses( $_POST['start'] ), wp_filter_nohtml_kses( $_POST['length'] ) )
55 )
56 );
57
58 // Get total amount of rows.
59 $count = $wpdb->get_var( 'SELECT COUNT(id) FROM ' . $wpdb->prefix . 'patchstack_firewall_log' );
60 $firewall_rules = json_decode( get_option( 'patchstack_firewall_rules', '' ), true );
61
62 // Modify data if necessary.
63 $list = array();
64 foreach ( $entries as $entry ) {
65 foreach ( $entry as $key => $value ) {
66 if ( ! in_array( $key, array( 'referer' ) ) ) {
67 $entry->$key = sanitize_textarea_field( $value );
68 }
69 }
70
71 // Attempt to find the block reason.
72 $reason = $wpdb->get_var( $wpdb->prepare( 'SELECT cname FROM ' . $wpdb->prefix . 'patchstack_logic WHERE id = %d LIMIT 1', array( $entry->fid ) ) );
73 if ( $reason ) {
74 $entry->fid = $reason;
75 } elseif ( $firewall_rules != '' ) {
76 foreach ( $firewall_rules as $rule ) {
77 if ( isset( $rule['title'], $rule['cat'] ) && '55' . $rule['id'] == $entry->fid ) {
78 $entry->fid = $rule['cat'];
79 $entry->description = $rule['title'];
80 }
81 }
82 } else {
83 $entry->fid = 'Unknown';
84 }
85
86 $list[] = $entry;
87 }
88
89 // Return output.
90 wp_send_json(
91 array(
92 'data' => $list,
93 'recordsFiltered' => $count,
94 'recordsTotal' => $count
95 )
96 );
97 }
98
99 /**
100 * Activity logs pagination.
101 *
102 * @return void
103 */
104 public function users_log_table() {
105 if ( ! isset( $_POST['start'], $_POST['length'] ) || !ctype_digit( $_POST['start'] ) || !ctype_digit( $_POST['length'] ) ) {
106 exit;
107 }
108
109 // Determine if searching?
110 global $wpdb;
111 $searching = false;
112 $likes = array();
113 if ( isset( $_POST['search'], $_POST['search']['value'] ) && $_POST['search']['value'] != '' ) {
114 $val = wp_filter_nohtml_kses( $_POST['search']['value'] );
115 $searching = true;
116 $columns = array( 'author', 'ip', 'object', 'object_name', 'action' );
117 $search = 'WHERE 1=2 ';
118 foreach ( $columns as $column ) {
119 array_push( $likes, '%' . $wpdb->esc_like( $val ) . '%' );
120 $search .= 'OR ' . $column . ' LIKE %s';
121 }
122 }
123
124 $logs = $wpdb->get_results(
125 $wpdb->prepare(
126 'SELECT *
127 FROM ' . $wpdb->prefix . 'patchstack_event_log ' . ( $searching ? $search : '' ) . '
128 ORDER BY id DESC
129 LIMIT %d, %d
130 ',
131 array_merge( $likes, array( wp_filter_nohtml_kses( $_POST['start'] ), wp_filter_nohtml_kses( $_POST['length'] ) ) )
132 )
133 );
134
135 $count = $wpdb->get_var( $wpdb->prepare( 'SELECT COUNT(id) FROM ' . $wpdb->prefix . 'patchstack_event_log ' . ( $searching ? $search : '' ), $likes ) );
136
137 // Modify data if necessary.
138 $list = array();
139 foreach ( $logs as $log ) {
140 $list[] = $log;
141 }
142
143 // Return output.
144 wp_send_json(
145 array(
146 'data' => $list,
147 'recordsFiltered' => $count,
148 'recordsTotal' => $count
149 )
150 );
151 }
152
153 /**
154 * Test and activate a new license.
155 *
156 * @return void
157 */
158 public function activate_license() {
159 if ( ! isset( $_POST['clientid'], $_POST['secretkey'] ) || !ctype_digit( $_POST['clientid'] ) ) {
160 wp_send_json(
161 array(
162 'result' => 'error',
163 'error_message' => 'Fill in all of the fields properly.'
164 )
165 );
166 }
167
168 // Test the new keys.
169 update_option( 'patchstack_api_token', '' );
170 $results = $this->plugin->activation->alter_license( wp_filter_nohtml_kses( $_POST['clientid'] ), wp_filter_nohtml_kses( $_POST['secretkey'] ), 'activate' );
171 if ( $results ) {
172 $response = $this->plugin->api->update_license_status();
173 $results['response'] = $response;
174 wp_send_json( $results );
175 }
176 }
177
178 /**
179 * Send an email to the current logged in user that contains the new admin page URL.
180 *
181 * @return void
182 */
183 public function send_new_url_email() {
184 global $current_user;
185 $subject = __( 'New Login URL', 'patchstack' );
186 $message = '<br /><br />Your login page is now here: <strong> <a href="' . get_site_url() . '/' . get_site_option( 'patchstack_rename_wp_login' ) . '">' . get_site_url() . '/' . get_site_option( 'patchstack_rename_wp_login' ) . '</strong></a>';
187 $email_sent = wp_mail( $current_user->user_email, $subject, $message );
188 die( $email_sent ? 'success' : 'fail' );
189 }
190 }
191