PluginProbe
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets / 4.5.6
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets v4.5.6
4.5.6 4.5.5 4.5.4 4.2.1 4.2.2 4.2.3 4.5.0 4.5.2 4.5.3 4.2.0 4.1.18 4.1.17 4.1.16 4.1.15 4.1.14 4.1.13 4.1.12 4.1.11 4.1.10 4.1.9 4.1.8 4.0.9 4.1.0 4.1.1 4.1.2 All 148 releases
← All changes | modules/alex-grid/module.php +46 -32 4.0.9 → 4.5.6 View file →
@@ -32,9 +32,21 @@
32 32 return $widgets;
33 33 }
34 34
35 35 public function callback_ajax_loadmore_posts() {
36 + // Verify the front-end nonce (sent by UltimatePostKitConfig.nonce) before
37 + // processing this public load-more request.
38 + if ( ! check_ajax_referer( 'upk-site', 'nonce', false ) ) {
39 + wp_send_json_error( array( 'message' => esc_html__( 'Security check failed.', 'ultimate-post-kit' ) ), 403 );
40 + }
36 41
42 +
43 + // Security: Verify nonce
44 + if ( ! isset( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_POST['nonce'] ) ), 'upk-site' ) ) {
45 + wp_send_json_error( [ 'message' => esc_html__( 'Security verification failed', 'ultimate-post-kit' ) ], 403 );
46 + wp_die();
47 + }
48 +
37 49 $settings = [];
38 50
39 51 if ( isset( $_POST['settings'] ) && is_array( $_POST['settings'] ) ) {
40 52 $settings = map_deep( wp_unslash( $_POST['settings'] ), 'sanitize_text_field' );
@@ -39,11 +51,16 @@
39 51 if ( isset( $_POST['settings'] ) && is_array( $_POST['settings'] ) ) {
40 52 $settings = map_deep( wp_unslash( $_POST['settings'] ), 'sanitize_text_field' );
41 53 }
42 54
43 - $post_type = $settings['post_source'] ?? 'post';
44 -
45 - $settings = array_merge(
55 + // NOTE: the request-derived values below are NOT the ones the query is built from.
56 + // query_args() is declared without parameters and re-reads $_POST['settings']
57 + // itself, so anything merged into $settings here is discarded. The query is
58 + // constrained inside query_args(): post_status is pinned to 'publish', per_page
59 + // is clamped to 1..100, and post_type is restricted to publicly visible post
60 + // types by ultimate_post_kit_sanitize_public_post_type(). The defaults are kept
61 + // only so the render loop below has the keys it expects.
62 + $settings = array_merge(
46 63 [
47 64 'posts_source' => 'post',
48 65 'posts_orderby' => 'date',
49 66 'posts_order' => 'DESC',
@@ -51,14 +68,15 @@
51 68 'posts_only_with_featured_image' => 'no',
52 69 'posts_select_date' => '',
53 70 'posts_exclude_by' => [],
54 71 'posts_include_by' => [],
55 - 'posts_per_page' => isset( $_POST['per_page'] ) ? absint( $_POST['per_page'] ) : 0,
56 - 'posts_offset' => isset( $_POST['offset'] ) ? absint( $_POST['offset'] ) : 0,
57 72 ],
58 73 $settings
59 74 );
60 -
75 +
76 + // Fill display flags the request may have omitted (see trait) before the render loop reads them.
77 + $settings = array_merge( $this->loadmore_display_defaults(), $settings );
78 +
61 79 $ajaxposts = $this->query_args( $settings );
62 80
63 81 ob_start();
64 82 $found_posts = false;
@@ -71,18 +89,16 @@
71 89 $title = get_the_title();
72 90 $post_link = esc_url(get_permalink());
73 91 $image_src = wp_get_attachment_image_url(get_post_thumbnail_id(), 'large');
74 92 $image_src = $image_src ? esc_url($image_src) : esc_url(\Elementor\Utils::get_placeholder_image_src());
75 - $category = wp_kses_post(upk_get_category($post_type));
93 + $category = wp_kses_post(upk_get_category($settings['posts_source'] ?? 'post'));
76 94 $author_url = esc_url(get_author_posts_url(get_the_author_meta('ID')));
77 95 $author_name = esc_html(get_the_author());
78 96 $title_tag = Utils::get_valid_html_tag($settings['title_tags'] );
79 97
80 - $onclick = '';
81 - if (!empty($settings['global_link']) && $settings['global_link'] === 'yes') {
82 - $onclick = ' onclick="window.open(\'' . $post_link . '\', \'_self\')"';
83 - }
84 -
98 + $meta_separator = isset( $settings['meta_separator'] ) ? $settings['meta_separator'] : '|';
99 +
100 +
85 101 $date = '';
86 102 if (!empty($settings['human_diff_time']) && $settings['human_diff_time'] === 'yes') {
87 103 $date = ultimate_post_kit_post_time_diff(($settings['human_diff_time_short'] === 'yes') ? 'short' : '');
88 104 } else {
@@ -103,11 +119,11 @@
103 119
104 120 $post_format_icon = isset($format_icons[get_post_format()]) ? $format_icons[get_post_format()] : 'upk-icon-post';
105 121
106 122 ?>
107 - <div <?php echo $onclick; ?> class="upk-item">
123 + <div <?php if ( ! empty( $settings['global_link'] ) && $settings['global_link'] === 'yes' ) { printf( 'onclick="window.open(\'%s\', \'_self\')"', esc_url( $post_link ) ); } ?> class="upk-item">
108 124 <div class="upk-image-wrap">
109 - <img class="upk-img" src="<?php echo $image_src; ?>" alt="<?php echo esc_attr($title); ?>">
125 + <img class="upk-img" src="<?php echo esc_url( $image_src ); ?>" alt="<?php echo esc_attr($title); ?>">
110 126
111 127 <?php if (
112 128 $settings['show_author'] === 'yes' ||
113 129 $settings['show_date'] === 'yes' ||
@@ -121,27 +137,25 @@
121 137
122 138 <div>
123 139 <?php if ($settings['show_author'] === 'yes') : ?>
124 140 <div class="upk-author-name">
125 - <a href="<?php echo $author_url; ?>"><?php echo $author_name; ?></a>
141 + <a href="<?php echo esc_url( $author_url ); ?>"><?php echo esc_html( $author_name ); ?></a>
126 142 </div>
127 143 <?php endif; ?>
128 144
129 145 <div class="upk-flex upk-flex-middle upk-date-reading-wrap">
130 - <?php if ($settings['show_date'] === 'yes') : ?>
131 - <div data-separator="<?php echo esc_attr($settings['meta_separator']); ?>">
132 - <div class="upk-date"><?php echo $date; ?></div>
133 - <?php if ($settings['show_time'] === 'yes') : ?>
134 - <div class="upk-post-time">
135 - <i class="upk-icon-clock" aria-hidden="true"></i><?php echo esc_html(get_the_time()); ?>
136 - </div>
137 - <?php endif; ?>
138 - </div>
146 + <?php if ( $settings['show_date'] === 'yes' ) : ?>
147 + <div class="upk-date"><?php echo esc_html( $date ); ?></div>
148 + <?php if ( $settings['show_time'] === 'yes' ) : ?>
149 + <div class="upk-post-time" data-separator="<?php echo esc_attr( $meta_separator ); ?>">
150 + <i class="upk-icon-clock" aria-hidden="true"></i><?php echo esc_html( get_the_time() ); ?>
151 + </div>
152 + <?php endif; ?>
139 153 <?php endif; ?>
140 -
141 - <?php if (function_exists('_is_upk_pro_activated') && _is_upk_pro_activated() && $settings['show_reading_time'] === 'yes') : ?>
142 - <div class="upk-reading-time" data-separator="<?php echo esc_attr($settings['meta_separator']); ?>">
143 - <?php echo ultimate_post_kit_reading_time(get_the_content(), $settings['avg_reading_speed']); ?>
154 +
155 + <?php if ( function_exists( '_is_upk_pro_activated' ) && _is_upk_pro_activated() && $settings['show_reading_time'] === 'yes' ) : ?>
156 + <div class="upk-reading-time" data-separator="<?php echo esc_attr( $meta_separator ); ?>">
157 + <?php echo wp_kses_post( ultimate_post_kit_reading_time( get_the_content(), $settings['avg_reading_speed'], $settings['hide_seconds'] ?? 'no', $settings['hide_minutes'] ?? 'no' ) ); ?>
144 158 </div>
145 159 <?php endif; ?>
146 160 </div>
147 161 </div>
@@ -149,9 +163,9 @@
149 163 <?php endif; ?>
150 164
151 165 <?php if ($settings['show_post_format'] === 'yes') : ?>
152 166 <div class="upk-post-format">
153 - <a href="<?php echo $post_link; ?>">
167 + <a href="<?php echo esc_url( $post_link ); ?>">
154 168 <i class="<?php echo esc_attr($post_format_icon); ?>" aria-hidden="true"></i>
155 169 </a>
156 170 </div>
157 171 <?php endif; ?>
@@ -159,15 +173,15 @@
159 173
160 174 <div class="upk-content-wrap">
161 175 <div class="upk-content">
162 176 <?php if ($settings['show_category'] === 'yes') : ?>
163 - <div class="upk-category"><?php echo $category; ?></div>
177 + <div class="upk-category"><?php echo wp_kses_post( $category ); ?></div>
164 178 <?php endif; ?>
165 179
166 180 <?php if ($settings['show_title'] === 'yes') : ?>
167 181 <<?php echo esc_attr( $title_tag ); ?> class="upk-title">
168 182 <a class="title-animation-<?php echo esc_attr($settings['title_style']); ?>"
169 - href="<?php echo $post_link; ?>"
183 + href="<?php echo esc_url( $post_link ); ?>"
170 184 title="<?php echo esc_attr($title); ?>"
171 185 <?php echo $settings['upk_link_new_tab'] === 'yes' ? 'target="_blank"' : ''; ?>
172 186 >
173 187 <?php echo esc_html($title); ?>
@@ -177,9 +191,9 @@
177 191 </div>
178 192
179 193 <?php if ($settings['show_readmore'] === 'yes') : ?>
180 194 <div class="upk-button-wrap">
181 - <a href="<?php echo $post_link; ?>"
195 + <a href="<?php echo esc_url( $post_link ); ?>"
182 196 class="upk-readmore"
183 197 target="<?php echo ($settings['upk_link_new_tab'] === 'yes') ? '_blank' : '_self'; ?>">
184 198 <span class="upk-readmore-icon"><span></span></span>
185 199 </a>