| @@ -1,30 +1,31 @@ | ||
| 1 | -<?php | |
| 2 | -/* | |
| 3 | -//load WP if needed | |
| 4 | -$path_to_wp_install_dir = ''; | |
| 5 | -include_once ( $path_to_wp_install_dir.'wp-load.php' ); | |
| 6 | -*/ | |
| 7 | - | |
| 8 | -$activation_key = ( isset( $_GET['activation_key'] ) ? urldecode( $_GET['activation_key'] ) : '' ); | |
| 9 | -$site_name = ( isset( $_GET['site_name'] ) ? urldecode( $_GET['site_name'] ) : '' ); | |
| 10 | -$site_url = ( isset( $_GET['site_url'] ) ? urldecode( $_GET['site_url'] ) : '' ); | |
| 11 | -$message = ( isset( $_GET['message'] ) ? urldecode( $_GET['message'] ) : '' ); | |
| 12 | -?> | |
| 13 | - | |
| 14 | -<html> | |
| 15 | - <head> | |
| 16 | - <style type="text/css"> | |
| 17 | - body {font-family:Arial; padding: 5px; margin-top:100px; text-align: center;} | |
| 18 | - </style> | |
| 19 | - | |
| 20 | - <title><?php echo htmlspecialchars( $site_name, ENT_QUOTES ); ?></title> | |
| 21 | - </head> | |
| 22 | - | |
| 23 | - <body id="wppb_content"> | |
| 24 | - <h1><?php echo htmlspecialchars( $site_name, ENT_QUOTES ); ?></h1> | |
| 25 | - | |
| 26 | - <?php echo '<p>'. htmlspecialchars( strip_tags( $message ) ). '</p>'; ?> | |
| 27 | - | |
| 28 | - <?php echo 'Click <a href="'. htmlspecialchars( $site_url, ENT_QUOTES ) .'">here</a> to return to the main site'; ?> | |
| 29 | - </body> | |
| 1 | +<?php | |
| 2 | +define( 'ABSPATH', __DIR__ . '/' );//added this because we actually need to access this page directly, sorry about this :) | |
| 3 | +/* | |
| 4 | +//load WP if needed | |
| 5 | +$path_to_wp_install_dir = ''; | |
| 6 | +include_once ( $path_to_wp_install_dir.'wp-load.php' ); | |
| 7 | +*/ | |
| 8 | + | |
| 9 | +if ( ! defined( 'ABSPATH' ) ) exit; // Exit if accessed directly | |
| 10 | + | |
| 11 | +$site_name = ( isset( $_GET['site_name'] ) ? filter_var ( urldecode( $_GET['site_name'] ), FILTER_SANITIZE_STRING ) : '' ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized | |
| 12 | +$message = ( isset( $_GET['message'] ) ? filter_var ( urldecode( $_GET['message'] ), FILTER_SANITIZE_STRING ) : '' ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized | |
| 13 | +?> | |
| 14 | + | |
| 15 | +<html> | |
| 16 | + <head> | |
| 17 | + <style type="text/css"> | |
| 18 | + body {font-family:Arial; padding: 5px; margin-top:100px; text-align: center;} | |
| 19 | + </style> | |
| 20 | + | |
| 21 | + <title><?php echo htmlspecialchars( $site_name, ENT_QUOTES ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?></title> | |
| 22 | + </head> | |
| 23 | + | |
| 24 | + <body id="wppb_content"> | |
| 25 | + <h1><?php echo htmlspecialchars( $site_name, ENT_QUOTES ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?></h1> | |
| 26 | + | |
| 27 | + <?php echo '<p>'. htmlspecialchars( strip_tags( $message ) ). '</p>'; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?> | |
| 28 | + | |
| 29 | + <?php echo 'Click <a href="/">here</a> to return to the main site'; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped ?> | |
| 30 | + </body> | |
| 30 | 31 | </html> |