PluginProbe
ShopBuilder – WooCommerce Builder For Elementor / 2.1.13
ShopBuilder – WooCommerce Builder For Elementor v2.1.13
3.4.2 3.4.1 3.4.0 2.0.1 2.0.2 2.0.3 2.1.0 2.1.1 2.1.10 2.1.11 2.1.12 2.1.13 2.1.14 2.1.15 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.2.0 2.2.1 2.2.2 All 63 releases
← All changes | app/Controllers/Admin/Ajax/CreateTemplate.php +28 -15 2.1.32.1.13 View file →
@@ -67,9 +67,9 @@
67 67 *
68 68 * @return void
69 69 */
70 70 public function response() {
71 - $page_type = isset( $_POST['page_type'] ) ? sanitize_text_field( wp_unslash( $_POST['page_type'] ) ) : null; //rtsb_tb_template_type - it represent to template type
71 + $page_type = isset( $_POST['page_type'] ) ? sanitize_text_field( wp_unslash( $_POST['page_type'] ) ) : null; // rtsb_tb_template_type - it represent to template type
72 72 $page_id = isset( $_POST['page_id'] ) ? absint( wp_unslash( $_POST['page_id'] ) ) : null;
73 73 $page_name = isset( $_POST['page_name'] ) ? sanitize_text_field( wp_unslash( $_POST['page_name'] ) ) : null;
74 74 $hasPro = isset( $_POST['hasPro'] ) ? sanitize_text_field( wp_unslash( $_POST['hasPro'] ) ) : null;
75 75 $edit_with = isset( $_POST['template_edit_with'] ) ? sanitize_text_field( wp_unslash( $_POST['template_edit_with'] ) ) : null;
@@ -78,9 +78,9 @@
78 78 $product_id = isset( $_POST['preview_product_id'] ) ? absint( $_POST['preview_product_id'] ) : null;
79 79
80 80 $url = '#';
81 81
82 - if ( ! Fns::verify_nonce() || ! $page_type ) {
82 + if ( ! wp_verify_nonce( Fns::get_nonce(), rtsb()->nonceText ) || ! $page_type ) {
83 83 $return = [
84 84 'success' => false,
85 85 'post_id' => $page_id,
86 86 ];
@@ -86,29 +86,41 @@
86 86 ];
87 87 wp_send_json( $return );
88 88
89 89 }
90 + if ( ! current_user_can( 'manage_options' ) ) {
91 + $return = [
92 + 'success' => false,
93 + 'post_id' => $page_id,
94 + ];
95 + wp_send_json( $return );
96 + }
90 97
91 - add_filter( 'pre_option_elementor_unfiltered_files_upload', function () {
92 - return '1';
93 - }, 99 );
98 + add_filter(
99 + 'pre_option_elementor_unfiltered_files_upload',
100 + function () {
101 + return '1';
102 + },
103 + 99
104 + );
94 105
95 106 Plugin::$instance->files_manager->clear_cache();
96 107 add_filter( 'rtsb_import_status', '__return_true' );
97 108
98 - $status = $_REQUEST['status'] ?? '';
109 + $status = sanitize_text_field( wp_unslash( $_REQUEST['status'] ?? '' ) );
99 110 $post_args = [ 'timeout' => 120 ];
100 111 $post_args['body'] = [
101 112 'status' => $status,
102 113 'layout_id' => $import_layout,
103 - 'has_pro' => $hasPro
114 + 'has_pro' => $hasPro,
104 115 ];
105 116 $layoutRequest = wp_remote_post( rtsb()->BASE_API, $post_args );
106 117
107 - if ( is_wp_error( $layoutRequest ) ) {
108 - wp_send_json_error( [ 'messages' => $layoutRequest->get_error_messages() ] );
118 + $layoutJson = [];
119 + if ( ! is_wp_error( $layoutRequest ) && ! empty( $layoutRequest['body'] ) ) {
120 + $layoutJson = json_decode( $layoutRequest['body'], true );
109 121 }
110 - $layoutJson = json_decode( $layoutRequest['body'], true );
122 +
111 123 $option_name = BuilderFns::option_name( $page_type );
112 124
113 125 $post_data = [
114 126 'ID' => $page_id,
@@ -147,15 +159,12 @@
147 159 $category_archive = array_unique( isset( $_POST['category_archive'] ) && is_array( $_POST['category_archive'] ) ? array_map( 'sanitize_text_field', $_POST['category_archive'] ) : [] );
148 160 $the_products = array_unique( isset( $_POST['the_products'] ) && is_array( $_POST['the_products'] ) ? array_map( 'absint', $_POST['the_products'] ) : [] );
149 161 if ( ! count( $the_products ) && ! count( $category_archive ) ) {
150 162 if ( 'default_template' === $default_template ) {
151 - // update_option( $option_name, $page_id );
152 163 TemplateSettings::instance()->set_option( $option_name, $page_id );
153 164 } else {
154 - // $has_default = get_option( $option_name );
155 165 $has_default = TemplateSettings::instance()->get_option( $option_name );
156 166 if ( ! $has_default ) {
157 - // update_option( $option_name, '' );
158 167 TemplateSettings::instance()->set_option( $option_name, '' );
159 168 }
160 169 }
161 170 }
@@ -174,9 +183,9 @@
174 183
175 184 if ( ! empty( $layoutJson['data'] ) ) {
176 185 $data = json_decode( $layoutJson['data'], true );
177 186 $content = $this->process_export_import_content( $data, 'on_import' );
178 - $content = json_encode( $content );
187 + $content = wp_json_encode( $content );
179 188 update_post_meta( $page_id, '_elementor_data', $content );
180 189 update_post_meta( $page_id, '_rtsb_import_id', $import_layout );
181 190 }
182 191 }
@@ -190,9 +199,13 @@
190 199 'new_page' => $new_page,
191 200
192 201 ];
193 202 if ( $edit_by ) {
194 - $return['edit_btn_text'] = esc_html__( sprintf( 'Edit with %s', $edit_by ), 'shopbuilder' );
203 + $return['edit_btn_text'] = sprintf(
204 + /* translators: %s: Edit */
205 + esc_html__( 'Edit with %s', 'shopbuilder' ),
206 + esc_html( $edit_by )
207 + );
195 208 }
196 209 wp_send_json( $return );
197 210 wp_die();
198 211 }