PluginProbe
Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls / 6.5.1
Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls v6.5.1
6.5.1 6.5.0 6.4.9 6.4.8 6.4.7 6.4.6 6.4.5 6.4.4 6.4.3 6.4.2 6.4.1 6.4.0 6.3.9 6.3.8 6.3.7 6.3.6 6.3.5 6.3.4 6.3.3 5.6.0 5.6.1 5.6.2 5.6.3 5.6.4 5.6.5 All 154 releases
← All changes | includes/lists/class-poll-maker-results-list-table.php +37 -23 5.6.4 → 6.5.1 View file →
@@ -10,10 +10,10 @@
10 10 public function __construct( $plugin_name ) {
11 11 $this->plugin_name = $plugin_name;
12 12 $this->title_length = Poll_Maker_Ays_Admin::get_listtables_title_length('results');
13 13 parent::__construct(array(
14 - 'singular' => __('Result', "poll-maker"), //singular name of the listed records
15 - 'plural' => __('Results', "poll-maker"), //plural name of the listed records
14 + 'singular' =>esc_html__('Result', "poll-maker"), //singular name of the listed records
15 + 'plural' =>esc_html__('Results', "poll-maker"), //plural name of the listed records
16 16 'ajax' => false, //does this table support ajax?
17 17 ));
18 18 add_action('admin_notices', array($this, 'results_notices'));
19 19
@@ -246,11 +246,19 @@
246 246
247 247 $res = $wpdb->get_row("SELECT * FROM {$wpdb->prefix}ayspoll_polls WHERE id={$item['id']}", "ARRAY_A");
248 248
249 249 $restitle = Poll_Maker_Ays_Admin::ays_restriction_string("word",stripcslashes($res['title']), $this->title_length);
250 - $title = sprintf('<a href="?page=%s-each&poll=%d&title=%s">' . $restitle . '</a>', esc_attr($_REQUEST['page']), absint($item['id']), stripslashes($res['title']));
250 + $title = sprintf('<a href="?page=%s-each&poll=%d&title=%s">' . $restitle . '</a>', esc_attr($_REQUEST['page']), absint($item['id']), stripslashes($res['title']));
251 +
251 252 $actions = [
252 - 'delete' => sprintf('<a href="?page=%s&action=%s&result=%s&_wpnonce=%s">Delete</a>', esc_attr($_REQUEST['page']), 'delete', absint($item['id']), $delete_nonce),
253 + 'delete' => sprintf(
254 + '<a href="?page=%s&action=%s&result=%s&_wpnonce=%s">%s</a>',
255 + esc_attr( $_REQUEST['page'] ),
256 + 'delete',
257 + absint( $item['id'] ),
258 + $delete_nonce,
259 + __( 'Delete', 'poll-maker' )
260 + ),
253 261 ];
254 262
255 263 return $title . $this->row_actions($actions);
256 264 }
@@ -317,12 +325,12 @@
317 325 */
318 326 function get_columns() {
319 327 $columns = array(
320 328 'cb' => '<input type="checkbox" />',
321 - 'id' => __('ID',"poll-maker"),
322 - 'poll_title' => __('Poll',"poll-maker"),
323 - 'voted' => __('Voters count',"poll-maker"),
324 - 'unread' => __('New results count',"poll-maker")
329 + 'poll_title' =>esc_html__('Poll',"poll-maker"),
330 + 'voted' =>esc_html__('Voters count',"poll-maker"),
331 + 'unread' =>esc_html__('New results count',"poll-maker"),
332 + 'id' =>esc_html__('ID',"poll-maker")
325 333 );
326 334
327 335 return $columns;
328 336 }
@@ -347,10 +355,10 @@
347 355 * @return array
348 356 */
349 357 public function get_bulk_actions() {
350 358 $actions = array(
351 - 'bulk-read' => __('Mark as read', "poll-maker"),
352 - 'bulk-delete' => __('Delete', "poll-maker"),
359 + 'bulk-read' =>esc_html__('Mark as read', "poll-maker"),
360 + 'bulk-delete' =>esc_html__('Delete', "poll-maker"),
353 361 );
354 362
355 363 return $actions;
356 364 }
@@ -402,18 +410,20 @@
402 410 wp_redirect($url);
403 411 }
404 412
405 413 }
406 -
407 - // If the delete bulk action is triggered
408 - if ((isset($_POST['action']) && 'bulk-delete' == $_POST['action'])
409 - || (isset($_POST['action2']) && 'bulk-delete' == $_POST['action2'])
414 +
415 + // Process bulk-delete action
416 + if ((isset($_POST['action']) && $_POST['action'] == 'bulk-delete')
417 + || (isset($_POST['action2']) && $_POST['action2'] == 'bulk-delete')
410 418 ) {
411 - $delete_ids = esc_sql($_POST['bulk-action']);
412 419
413 - // loop over the array of record IDs and delete them
414 - foreach ( $delete_ids as $id ) {
415 - self::delete_reports($id);
420 + if (!empty($_POST['bulk-action']) && is_array($_POST['bulk-action'])) {
421 + $delete_ids = array_map('intval', $_POST['bulk-action']);
422 +
423 + foreach ($delete_ids as $id) {
424 + self::delete_reports($id);
425 + }
416 426 }
417 427
418 428 // esc_url_raw() is used to prevent converting ampersand in url to "#038;"
419 429 // add_query_arg() return the current url
@@ -424,10 +434,14 @@
424 434 } elseif ((isset($_POST['action']) && 'bulk-read' == $_POST['action'])
425 435 || (isset($_POST['action2']) && 'bulk-read' == $_POST['action2'])
426 436 ) {
427 437
428 - $read_ids = esc_sql($_POST['bulk-action']);
438 + if (empty($_POST['bulk-action']) || !is_array($_POST['bulk-action'])) {
439 + return;
440 + }
429 441
442 + $read_ids = array_map('intval', $_POST['bulk-action']);
443 +
430 444 // loop over the array of record IDs and mark as readed them
431 445 foreach ( $read_ids as $id ) {
432 446 echo $id . "<br>";
433 447 self::mark_as_read_reports($id);
@@ -465,9 +479,9 @@
465 479 return;
466 480 }
467 481
468 482 if ('deleted' == $status) {
469 - $updated_message = esc_html(__('Result deleted.', "poll-maker"));
483 + $updated_message = esc_html( esc_html__('Result deleted.', "poll-maker"));
470 484 }
471 485
472 486 if (empty($updated_message)) {
473 487 return;
@@ -473,9 +487,9 @@
473 487 return;
474 488 }
475 489
476 490 ?>
477 - <div class="notice notice-success is-dismissible">
491 + <div class="ays-poll-admin-notice notice notice-success is-dismissible">
478 492 <p> <?php echo $updated_message; ?> </p>
479 493 </div>
480 494 <?php
481 495 }
@@ -501,9 +515,9 @@
501 515 $content = "";
502 516 if(isset($poll_cats)){
503 517 $content = '<label for="bulk-action-selector-top-cat" class="screen-reader-text">Select Filter Type</label>
504 518 <select name="orderbycat" id="bulk-action-selector-top-cat">
505 - <option value="0" selected>' .__("Select Category", "poll-maker"). '</option>';
519 + <option value="0" selected>' . esc_html__("Select Category", "poll-maker"). '</option>';
506 520 $selected = "";
507 521 $this_cat_id = 0;
508 522 foreach ($poll_cats as $cat_key => $cat_value) {
509 523 $selected = (isset($_REQUEST['orderbycat']) && $_REQUEST['orderbycat'] == $cat_value['id'] ) ? 'selected' : '';
@@ -512,9 +526,9 @@
512 526 $cat_value = isset($cat_value['title']) && $cat_value['title'] != "" ? esc_attr($cat_value['title']) : "";
513 527 $content .= '<option value="'.$cat_id.'" '.$selected.'>'.$cat_value.'</option>';
514 528 }
515 529 $content .= '</select>';
516 - $content .= '<input type="submit" id="doactioncat" name="filter_by_cat" class="button action" value="'.__("Filter", "poll-maker").'" style="width: 3.7rem;margin-left: 5px;">';
530 + $content .= '<input type="submit" id="doactioncat" name="filter_by_cat" class="button action" value="'. esc_html__("Filter", "poll-maker").'" style="width: 3.7rem;margin-left: 5px;">';
517 531 if(isset($_REQUEST['filter_by_cat'])){
518 532 $new_url = remove_query_arg("orderbycat")."&orderbycat=".$this_cat_id;
519 533 wp_redirect($new_url);
520 534 }