| @@ -14,8 +14,9 @@ | ||
| 14 | 14 | |
| 15 | 15 | /** |
| 16 | 16 | * PH_Settings_Page |
| 17 | 17 | */ |
| 18 | +// phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedClassFound -- Legacy public global class PH_Settings_Page; preserving the existing PH_* class name is required for plugin and extension compatibility. | |
| 18 | 19 | class PH_Settings_Page { |
| 19 | 20 | |
| 20 | 21 | protected $id = ''; |
| 21 | 22 | protected $label = ''; |
| @@ -80,8 +81,12 @@ | ||
| 80 | 81 | /** |
| 81 | 82 | * Save settings |
| 82 | 83 | */ |
| 83 | 84 | public function save() { |
| 85 | + if ( ! current_user_can( 'manage_options' ) || ! isset( $_REQUEST['_wpnonce'] ) || ! is_string( $_REQUEST['_wpnonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_REQUEST['_wpnonce'] ) ), 'propertyhive-settings' ) ) { | |
| 86 | + return; | |
| 87 | + } | |
| 88 | + | |
| 84 | 89 | global $current_section; |
| 85 | 90 | |
| 86 | 91 | $settings = $this->get_settings(); |
| 87 | 92 | PH_Admin_Settings::save_fields( $settings ); |