PluginProbe
TablePress – Tables in WordPress made easy / 3.4
TablePress – Tables in WordPress made easy v3.4
3.4 3.3.4 3.3.3 3.3.2 3.3.1 trunk 1.12 1.14 1.9.2 2.0.4 2.1.7 2.1.8 2.2 2.2.1 2.2.2 2.2.3 2.2.4 2.2.5 2.3 2.3.1 2.3.2 2.4 2.4.1 2.4.2 2.4.3 All 45 releases
← All changes | classes/class-evaluate-phpspreadsheet.php +15 -10 2.2 → 3.4 View file →
@@ -7,8 +7,10 @@
7 7 * @author Tobias Bäthge
8 8 * @since 2.0.0
9 9 */
10 10
11 +declare(strict_types=1);
12 +
11 13 // Prohibit direct script loading.
12 14 defined( 'ABSPATH' ) || die( 'No direct script access allowed!' );
13 15
14 16 /**
@@ -26,10 +28,10 @@
26 28 *
27 29 * @since 2.0.0
28 30 */
29 31 public function __construct() {
30 - // Load PHPSpreadsheet via the Composer autoloading mechanism.
31 - TablePress::load_file( 'autoload.php', 'libraries' );
32 + // Load PHPSpreadsheet via its autoloading mechanism.
33 + TablePress::load_file( 'autoload.php', 'libraries/vendor' );
32 34 }
33 35
34 36 /**
35 37 * Evaluates formulas in the passed table.
@@ -51,13 +53,13 @@
51 53 }
52 54
53 55 $table_has_formulas = true;
54 56
55 - // Convert legacy "formulas in text" notation to standard Excel notation (`=Text {A3+B3} Text` => `="Text "&A3+B3&" Text"`).
56 - $count = 0;
57 - $cell_content = (string) preg_replace( '#{(.+?)}#', '"&$1&"', $cell_content, -1, $count );
58 - if ( $count > 0 ) {
59 - $cell_content = '="' . substr( $cell_content, 1 ) . '"';
57 + // Convert legacy "formulas in text" notation (`=Text {A3+B3} Text`) to standard Excel notation (`="Text "&A3+B3&" Text"`).
58 + if ( 1 === preg_match( '#{(.+?)}#', $cell_content ) ) {
59 + $cell_content = str_replace( '"', '""', $cell_content ); // Preserve existing quotation marks in text around formulas.
60 + $cell_content = '="' . substr( $cell_content, 1 ) . '"'; // Wrap the whole cell content in quotation marks, as there will be text around formulas.
61 + $cell_content = (string) preg_replace( '#{(.+?)}#', '"&$1&"', $cell_content, -1, $count ); // Convert all wrapped formulas to standard Excel notation.
60 62 }
61 63 }
62 64 }
63 65 unset( $row, $cell_content ); // Unset use-by-reference parameters of foreach loops.
@@ -72,9 +74,9 @@
72 74 $worksheet = $spreadsheet->setActiveSheetIndex( 0 );
73 75 $worksheet->fromArray( /* $source */ $table_data, /* $nullValue */ '' );
74 76
75 77 // Don't allow cyclic references.
76 - TablePress\PhpOffice\PhpSpreadsheet\Calculation\Calculation::getInstance( $spreadsheet )->cyclicFormulaCount = 0;
78 + \TablePress\PhpOffice\PhpSpreadsheet\Calculation\Calculation::getInstance( $spreadsheet )->cyclicFormulaCount = 0;
77 79
78 80 /*
79 81 * Register variables as Named Formulas.
80 82 * The variables `ROW`, `COLUMN`, `CELL`, `PI`, and `E` should be considered deprecated and only their formulas should be used.
@@ -110,9 +112,12 @@
110 112 $url = esc_url( $url );
111 113 $cell_content = "<a href=\"{$url}\">{$cell_content}</a>";
112 114 }
113 115 }
114 - } catch ( \TablePress\PhpOffice\PhpSpreadsheet\Calculation\Exception $exception ) {
116 +
117 + // Sanitize the output of the evaluated formula.
118 + $cell_content = wp_kses_post( $cell_content ); // Equals wp_filter_post_kses(), but without the unnecessary slashes handling.
119 + } catch ( \Throwable $exception ) {
115 120 $message = str_replace( 'Worksheet!', '', $exception->getMessage() );
116 121 $cell_content = "!ERROR! {$message}";
117 122 }
118 123 }
@@ -123,9 +128,9 @@
123 128
124 129 // Save PHP memory.
125 130 $spreadsheet->disconnectWorksheets();
126 131 unset( $cell_collection, $worksheet, $spreadsheet );
127 - } catch ( \TablePress\PhpOffice\PhpSpreadsheet\Calculation\Exception $exception ) {
132 + } catch ( \Throwable $exception ) {
128 133 $message = str_replace( 'Worksheet!', '', $exception->getMessage() );
129 134 $table_data = array( array( "!ERROR! {$message}" ) );
130 135 }
131 136