PluginProbe
Patchstack – WordPress & Plugins Security / 2.2.4
Patchstack – WordPress & Plugins Security v2.2.4
2.3.7 trunk 2.1.0 2.1.1 2.1.10 2.1.11 2.1.12 2.1.13 2.1.14 2.1.15 2.1.16 2.1.17 2.1.18 2.1.19 2.1.2 2.1.20 2.1.21 2.1.22 2.1.23 2.1.24 2.1.25 2.1.3 2.1.4 2.1.5 2.1.6 All 49 releases
← All changes | includes/multisite.php +46 -9 2.1.12.2.4 View file →
@@ -10,9 +10,9 @@
10 10 */
11 11 class P_Multisite extends P_Core {
12 12
13 13 /**
14 - * Stores any license activation errors.
14 + * Stores any errors.
15 15 *
16 16 * @var string
17 17 */
18 18 public $error = '';
@@ -37,8 +37,13 @@
37 37 // When sites are activated.
38 38 if ( isset( $_POST['patchstack_do'], $_POST['PatchstackNonce'], $_POST['sites'] ) && $_POST['patchstack_do'] == 'do_licenses' && wp_verify_nonce( $_POST['PatchstackNonce'], 'patchstack-multisite-activation' ) ) {
39 39 $this->activate_licenses();
40 40 }
41 +
42 + // When we need to re-run the migration of a specific site.
43 + if ( isset( $_GET['site'], $_GET['PatchstackNonce'] ) && wp_verify_nonce( $_GET['PatchstackNonce'], 'patchstack-migration' ) ) {
44 + $this->run_migration();
45 + }
41 46 }
42 47
43 48 /**
44 49 * When a user selects sites that need to be activated.
@@ -51,9 +56,9 @@
51 56 return;
52 57 }
53 58
54 59 // Determine which sites are already activated and skip those.
55 - $activate = array();
60 + $activate = [];
56 61 $sites = get_sites();
57 62 foreach ( $sites as $site ) {
58 63 if ( in_array( $site->siteurl, $_POST['sites'] ) && get_blog_option( $site->id, 'patchstack_clientid' ) == '' ) {
59 64 array_push( $activate, $site->siteurl );
@@ -66,9 +71,9 @@
66 71 return;
67 72 }
68 73
69 74 // Add the site to the app and retrieve the license for each site.
70 - $licenses = $this->plugin->api->get_site_licenses( array( 'sites' => $activate ) );
75 + $licenses = $this->plugin->api->get_site_licenses( [ 'sites' => $activate ] );
71 76
72 77 // Did an error happen during the multisite license activation?
73 78 if ( isset( $licenses['error'] ) ) {
74 79 $this->error = '<span style="color: #ff6262;">' . $licenses['error'] . '</span><br /><br />';
@@ -92,27 +97,27 @@
92 97 private function save_settings() {
93 98 switch ( $_POST['option_page'] ) {
94 99 // Save hardening options
95 100 case 'patchstack_hardening_settings_group':
96 - $options = array( 'patchstack_auto_update', 'patchstack_json_is_disabled', 'patchstack_register_email_blacklist', 'patchstack_move_logs', 'patchstack_basicscanblock', 'patchstack_userenum', 'patchstack_hidewpversion', 'patchstack_activity_log_is_enabled', 'patchstack_activity_log_failed_logins', 'patchstack_xmlrpc_is_disabled', 'patchstack_captcha_on_comments', 'patchstack_captcha_login_form', 'patchstack_captcha_registration_form', 'patchstack_captcha_reset_pwd_form', 'patchstack_captcha_type', 'patchstack_captcha_public_key', 'patchstack_captcha_public_key_v3', 'patchstack_captcha_public_key_v3_new', 'patchstack_captcha_private_key', 'patchstack_captcha_private_key_v3', 'patchstack_captcha_private_key_v3_new', 'patchstack_application_passwords_disabled' );
101 + $options = [ 'patchstack_auto_update', 'patchstack_json_is_disabled', 'patchstack_register_email_blacklist', 'patchstack_move_logs', 'patchstack_basicscanblock', 'patchstack_userenum', 'patchstack_hidewpversion', 'patchstack_activity_log_is_enabled', 'patchstack_activity_log_failed_logins', 'patchstack_xmlrpc_is_disabled', 'patchstack_captcha_on_comments', 'patchstack_captcha_login_form', 'patchstack_captcha_registration_form', 'patchstack_captcha_reset_pwd_form', 'patchstack_captcha_type', 'patchstack_captcha_public_key', 'patchstack_captcha_public_key_v3', 'patchstack_captcha_public_key_v3_new', 'patchstack_captcha_private_key', 'patchstack_captcha_private_key_v3', 'patchstack_captcha_private_key_v3_new', 'patchstack_application_passwords_disabled' ];
97 102 $this->save_options( $options );
98 103 break;
99 104
100 105 // Save firewall settings
101 106 case 'patchstack_firewall_settings_group':
102 - $options = array( 'patchstack_geo_block_countries', 'patchstack_geo_block_enabled', 'patchstack_geo_block_inverse', 'patchstack_ip_block_list', 'patchstack_basic_firewall', 'patchstack_autoblock_blocktime', 'patchstack_autoblock_attempts', 'patchstack_autoblock_minutes', 'patchstack_basic_firewall_roles', 'patchstack_disable_htaccess', 'patchstack_add_security_headers', 'patchstack_prevent_default_file_access', 'patchstack_block_debug_log_access', 'patchstack_index_views', 'patchstack_proxy_comment_posting', 'patchstack_image_hotlinking', 'patchstack_firewall_custom_rules', 'patchstack_firewall_custom_rules_loc', 'patchstack_blackhole_log', 'patchstack_whitelist' );
107 + $options = [ 'patchstack_geo_block_countries', 'patchstack_geo_block_enabled', 'patchstack_geo_block_inverse', 'patchstack_ip_block_list', 'patchstack_basic_firewall', 'patchstack_autoblock_blocktime', 'patchstack_autoblock_attempts', 'patchstack_autoblock_minutes', 'patchstack_basic_firewall_roles', 'patchstack_disable_htaccess', 'patchstack_add_security_headers', 'patchstack_prevent_default_file_access', 'patchstack_block_debug_log_access', 'patchstack_index_views', 'patchstack_proxy_comment_posting', 'patchstack_image_hotlinking', 'patchstack_firewall_custom_rules', 'patchstack_firewall_custom_rules_loc', 'patchstack_blackhole_log', 'patchstack_whitelist' ];
103 108 $this->save_options( $options );
104 109 break;
105 110
106 111 // Save login settings
107 112 case 'patchstack_login_settings_group':
108 - $options = array( 'patchstack_mv_wp_login', 'patchstack_rename_wp_login', 'patchstack_block_bruteforce_ips', 'patchstack_anti_bruteforce_blocktime', 'patchstack_anti_bruteforce_attempts', 'patchstack_anti_bruteforce_minutes', 'patchstack_login_time_block', 'patchstack_login_time_start', 'patchstack_login_time_end', 'patchstack_login_2fa', 'patchstack_login_whitelist' );
113 + $options = [ 'patchstack_mv_wp_login', 'patchstack_rename_wp_login', 'patchstack_block_bruteforce_ips', 'patchstack_anti_bruteforce_blocktime', 'patchstack_anti_bruteforce_attempts', 'patchstack_anti_bruteforce_minutes', 'patchstack_login_time_block', 'patchstack_login_time_start', 'patchstack_login_time_end', 'patchstack_login_2fa', 'patchstack_login_whitelist' ];
109 114 $this->save_options( $options );
110 115 break;
111 116
112 117 // Save cookie notice settings
113 118 case 'patchstack_cookienotice_settings_group':
114 - $options = array( 'patchstack_enable_cookie_notice_message', 'patchstack_cookie_notice_message', 'patchstack_cookie_notice_accept_text', 'patchstack_cookie_notice_backgroundcolor', 'patchstack_cookie_notice_textcolor', 'patchstack_cookie_notice_privacypolicy_enable', 'patchstack_cookie_notice_privacypolicy_text', 'patchstack_cookie_notice_privacypolicy_link', 'patchstack_cookie_notice_cookie_expiration', 'patchstack_cookie_notice_opacity', 'patchstack_cookie_notice_credits' );
119 + $options = [ 'patchstack_enable_cookie_notice_message', 'patchstack_cookie_notice_message', 'patchstack_cookie_notice_accept_text', 'patchstack_cookie_notice_backgroundcolor', 'patchstack_cookie_notice_textcolor', 'patchstack_cookie_notice_privacypolicy_enable', 'patchstack_cookie_notice_privacypolicy_text', 'patchstack_cookie_notice_privacypolicy_link', 'patchstack_cookie_notice_cookie_expiration', 'patchstack_cookie_notice_opacity', 'patchstack_cookie_notice_credits' ];
115 120 $this->save_options( $options );
116 121 break;
117 122 }
118 123 }
@@ -135,15 +140,47 @@
135 140 */
136 141 private function save_options( $options ) {
137 142 if ( isset( $_GET['page'] ) && $_GET['page'] == 'patchstack-multisite-settings' ) {
138 143 foreach ( $options as $option ) {
139 - $value = isset( $_POST[ $option ] ) ? wp_filter_nohtml_kses( $_POST[ $option ] ) : 0;
144 + $value = isset( $_POST[ $option ] ) ? $_POST[ $option ] : 0;
145 + $value = map_deep( $value, 'wp_filter_nohtml_kses' );
140 146 update_site_option( $option, $value );
141 147 }
142 148 } else {
143 149 foreach ( $options as $option ) {
144 - $value = isset( $_POST[ $option ] ) ? wp_filter_nohtml_kses( $_POST[ $option ] ) : 0;
150 + $value = isset( $_POST[ $option ] ) ? $_POST[ $option ] : 0;
151 + $value = map_deep( $value, 'wp_filter_nohtml_kses' );
145 152 update_option( $option, $value );
146 153 }
147 154 }
155 + }
156 +
157 + /**
158 + * Re-run the migration for a specific multisite site.
159 + *
160 + * @return void
161 + */
162 + private function run_migration( ) {
163 + // Must be a number.
164 + if ( !ctype_digit( $_GET['site'] ) ) {
165 + exit;
166 + }
167 +
168 + // Site must be valid and exists.
169 + $site = get_site( $_GET['site'] );
170 + if ( is_null( $site ) ) {
171 + exit;
172 + }
173 +
174 + // Perform base migration.
175 + $this->plugin->activation->migrate( null, $site->id );
176 +
177 + // Perform specific version migrations.
178 + $versions = array('3.0.1', '3.0.2');
179 + foreach ( $versions as $version ) {
180 + $this->plugin->activation->migrate( $version, $site->id );
181 + }
182 +
183 + wp_safe_redirect( add_query_arg( [ 'success' => '1', 'site' => $site->id ], remove_query_arg( [ 'PatchstackNonce', 'site' ] ) ) );
184 + exit;
148 185 }
149 186 }