PluginProbe
SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster / 2.3.0
SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster v2.3.0
2.8.0 2.7.0 2.6.0 trunk 1.1.0 1.1.4 1.2.1 1.2.2 1.2.3 1.2.5 1.2.9 1.3.1 1.3.2 1.5.0 1.5.1 1.5.4 1.5.7 1.5.8 1.5.9 1.6.2 1.6.5 1.6.8 1.7.2 1.7.4 1.7.5 All 44 releases
← All changes | includes/elementor/modules/checkout/fields/select.php +36 -7 1.7.9 → 2.3.0 View file →
@@ -62,9 +62,9 @@
62 62 * @return void
63 63 * @since 1.1.0
64 64 */
65 65 public function field( $field, $args, $key ) {
66 - echo '<i class="fa fa-angle-down sellkit-select-appearance"></i>';
66 + echo '<span class="sellkit-select-appearance"><svg xmlns="http://www.w3.org/2000/svg" height="1em" viewBox="0 0 448 512"><path d="M201.4 342.6c12.5 12.5 32.8 12.5 45.3 0l160-160c12.5-12.5 12.5-32.8 0-45.3s-32.8-12.5-45.3 0L224 274.7 86.6 137.4c-12.5-12.5-32.8-12.5-45.3 0s-12.5 32.8 0 45.3l160 160z"/></svg></span>';
67 67
68 68 if ( 'shipping_country' === $key || 'billing_country' === $key ) {
69 69 $default = '';
70 70 if ( array_key_exists( 'default', $args ) ) {
@@ -96,9 +96,9 @@
96 96
97 97 $placeholder = $this->placeholder_required_value( $args );
98 98
99 99 ?>
100 - <p id="<?php echo $key; ?>_field">
100 + <p id="<?php echo esc_attr( $key ); ?>_field">
101 101 <span class="woocommerce-input-wrapper">
102 102 <select
103 103 name="<?php echo esc_attr( $key ); ?>"
104 104 id="<?php echo esc_attr( $key ); ?>"
@@ -146,9 +146,9 @@
146 146 * @return void
147 147 */
148 148 private function woocommerce_field_country( $key, $default ) {
149 149 ?>
150 - <p id="<?php echo $key; ?>_field">
150 + <p id="<?php echo esc_attr( $key ); ?>_field">
151 151 <span class="woocommerce-input-wrapper">
152 152 <?php
153 153 $countries = WC()->countries->get_shipping_countries();
154 154
@@ -170,9 +170,27 @@
170 170
171 171 $field .= '</select>';
172 172 $field .= '<noscript><input type="submit" name="woocommerce_checkout_update_totals" value="' . esc_attr__( 'Update country', 'sellkit' ) . '" /></noscript>';
173 173
174 - echo $field;
174 + $allowed_html = [
175 + 'select' => [
176 + 'name' => true,
177 + 'id' => true,
178 + 'class' => true,
179 + ],
180 + 'option' => [
181 + 'value' => true,
182 + 'selected' => true,
183 + ],
184 + 'noscript' => [],
185 + 'input' => [
186 + 'type' => true,
187 + 'name' => true,
188 + 'value' => true,
189 + ],
190 + ];
191 +
192 + echo wp_kses( $field, $allowed_html );
175 193 ?>
176 194 </span>
177 195 </p>
178 196 <?php
@@ -190,9 +208,9 @@
190 208 private function woocommerce_field_state( $key, $args, $states ) {
191 209 $placeholder = $this->placeholder_required_value( $args );
192 210
193 211 ?>
194 - <p id="<?php echo $key; ?>_field">
212 + <p id="<?php echo esc_attr( $key ); ?>_field">
195 213 <span class="woocommerce-input-wrapper">
196 214 <?php
197 215 if ( ! is_array( $states ) || empty( $states ) ) {
198 216 $state = filter_input( INPUT_COOKIE, 'sellkit-checkout-billing-state' );
@@ -216,9 +234,9 @@
216 234
217 235 return;
218 236 }
219 237
220 - $field = '<select id="sellkit-' . $key . '" name="' . esc_attr( $key ) . '" placeholder="' . esc_attr( $args['label'] ) . '">
238 + $field = '<select id="sellkit-' . esc_attr( $key ) . '" name="' . esc_attr( $key ) . '" placeholder="' . esc_attr( $args['label'] ) . '">
221 239 <option value="">' . esc_html__( 'Select a state…', 'sellkit' ) . '</option>';
222 240
223 241 foreach ( $states as $state_key => $state_label ) {
224 242 $field .= '<option value="' . esc_attr( $state_key ) . '" >' . esc_html( $state_label ) . '</option>';
@@ -225,9 +243,20 @@
225 243 }
226 244
227 245 $field .= '</select>';
228 246
229 - echo $field;
247 + $allowed_html = [
248 + 'select' => [
249 + 'id' => true,
250 + 'name' => true,
251 + 'placeholder' => true,
252 + ],
253 + 'option' => [
254 + 'value' => true,
255 + ],
256 + ];
257 +
258 + echo wp_kses( $field, $allowed_html );
230 259 ?>
231 260 </span>
232 261 </p>
233 262 <?php