| @@ -7,8 +7,10 @@ | ||
| 7 | 7 | * @author Tobias Bäthge |
| 8 | 8 | * @since 2.0.0 |
| 9 | 9 | */ |
| 10 | 10 | |
| 11 | +declare(strict_types=1); | |
| 12 | + | |
| 11 | 13 | // Prohibit direct script loading. |
| 12 | 14 | defined( 'ABSPATH' ) || die( 'No direct script access allowed!' ); |
| 13 | 15 | |
| 14 | 16 | /** |
| @@ -27,9 +29,9 @@ | ||
| 27 | 29 | * @since 2.0.0 |
| 28 | 30 | */ |
| 29 | 31 | public function __construct() { |
| 30 | 32 | // Load PHPSpreadsheet via its autoloading mechanism. |
| 31 | - TablePress::load_file( 'autoload.php', 'libraries' ); | |
| 33 | + TablePress::load_file( 'autoload.php', 'libraries/vendor' ); | |
| 32 | 34 | } |
| 33 | 35 | |
| 34 | 36 | /** |
| 35 | 37 | * Evaluates formulas in the passed table. |
| @@ -110,9 +112,12 @@ | ||
| 110 | 112 | $url = esc_url( $url ); |
| 111 | 113 | $cell_content = "<a href=\"{$url}\">{$cell_content}</a>"; |
| 112 | 114 | } |
| 113 | 115 | } |
| 114 | - } catch ( \TablePress\PhpOffice\PhpSpreadsheet\Calculation\Exception $exception ) { | |
| 116 | + | |
| 117 | + // Sanitize the output of the evaluated formula. | |
| 118 | + $cell_content = wp_kses_post( $cell_content ); // Equals wp_filter_post_kses(), but without the unnecessary slashes handling. | |
| 119 | + } catch ( \Throwable $exception ) { | |
| 115 | 120 | $message = str_replace( 'Worksheet!', '', $exception->getMessage() ); |
| 116 | 121 | $cell_content = "!ERROR! {$message}"; |
| 117 | 122 | } |
| 118 | 123 | } |
| @@ -123,9 +128,9 @@ | ||
| 123 | 128 | |
| 124 | 129 | // Save PHP memory. |
| 125 | 130 | $spreadsheet->disconnectWorksheets(); |
| 126 | 131 | unset( $cell_collection, $worksheet, $spreadsheet ); |
| 127 | - } catch ( \TablePress\PhpOffice\PhpSpreadsheet\Calculation\Exception $exception ) { | |
| 132 | + } catch ( \Throwable $exception ) { | |
| 128 | 133 | $message = str_replace( 'Worksheet!', '', $exception->getMessage() ); |
| 129 | 134 | $table_data = array( array( "!ERROR! {$message}" ) ); |
| 130 | 135 | } |
| 131 | 136 | |