| @@ -32,9 +32,21 @@ | ||
| 32 | 32 | return $widgets; |
| 33 | 33 | } |
| 34 | 34 | |
| 35 | 35 | public function callback_ajax_loadmore_posts() { |
| 36 | + // Verify the front-end nonce (sent by UltimatePostKitConfig.nonce) before | |
| 37 | + // processing this public load-more request. | |
| 38 | + if ( ! check_ajax_referer( 'upk-site', 'nonce', false ) ) { | |
| 39 | + wp_send_json_error( array( 'message' => esc_html__( 'Security check failed.', 'ultimate-post-kit' ) ), 403 ); | |
| 40 | + } | |
| 36 | 41 | |
| 42 | + | |
| 43 | + // Security: Verify nonce | |
| 44 | + if ( ! isset( $_POST['nonce'] ) || ! wp_verify_nonce( sanitize_text_field( wp_unslash( $_POST['nonce'] ) ), 'upk-site' ) ) { | |
| 45 | + wp_send_json_error( [ 'message' => esc_html__( 'Security verification failed', 'ultimate-post-kit' ) ], 403 ); | |
| 46 | + wp_die(); | |
| 47 | + } | |
| 48 | + | |
| 37 | 49 | $settings = []; |
| 38 | 50 | |
| 39 | 51 | if ( isset( $_POST['settings'] ) && is_array( $_POST['settings'] ) ) { |
| 40 | 52 | $settings = map_deep( wp_unslash( $_POST['settings'] ), 'sanitize_text_field' ); |
| @@ -39,11 +51,16 @@ | ||
| 39 | 51 | if ( isset( $_POST['settings'] ) && is_array( $_POST['settings'] ) ) { |
| 40 | 52 | $settings = map_deep( wp_unslash( $_POST['settings'] ), 'sanitize_text_field' ); |
| 41 | 53 | } |
| 42 | 54 | |
| 43 | - $post_type = $settings['post_source'] ?? 'post'; | |
| 44 | - | |
| 45 | - $settings = array_merge( | |
| 55 | + // NOTE: the request-derived values below are NOT the ones the query is built from. | |
| 56 | + // query_args() is declared without parameters and re-reads $_POST['settings'] | |
| 57 | + // itself, so anything merged into $settings here is discarded. The query is | |
| 58 | + // constrained inside query_args(): post_status is pinned to 'publish', per_page | |
| 59 | + // is clamped to 1..100, and post_type is restricted to publicly visible post | |
| 60 | + // types by ultimate_post_kit_sanitize_public_post_type(). The defaults are kept | |
| 61 | + // only so the render loop below has the keys it expects. | |
| 62 | + $settings = array_merge( | |
| 46 | 63 | [ |
| 47 | 64 | 'posts_source' => 'post', |
| 48 | 65 | 'posts_orderby' => 'date', |
| 49 | 66 | 'posts_order' => 'DESC', |
| @@ -51,14 +68,15 @@ | ||
| 51 | 68 | 'posts_only_with_featured_image' => 'no', |
| 52 | 69 | 'posts_select_date' => '', |
| 53 | 70 | 'posts_exclude_by' => [], |
| 54 | 71 | 'posts_include_by' => [], |
| 55 | - 'posts_per_page' => isset( $_POST['per_page'] ) ? absint( $_POST['per_page'] ) : 0, | |
| 56 | - 'posts_offset' => isset( $_POST['offset'] ) ? absint( $_POST['offset'] ) : 0, | |
| 57 | 72 | ], |
| 58 | 73 | $settings |
| 59 | 74 | ); |
| 60 | - | |
| 75 | + | |
| 76 | + // Fill display flags the request may have omitted (see trait) before the render loop reads them. | |
| 77 | + $settings = array_merge( $this->loadmore_display_defaults(), $settings ); | |
| 78 | + | |
| 61 | 79 | $ajaxposts = $this->query_args( $settings ); |
| 62 | 80 | |
| 63 | 81 | ob_start(); |
| 64 | 82 | $found_posts = false; |
| @@ -71,18 +89,16 @@ | ||
| 71 | 89 | $title = get_the_title(); |
| 72 | 90 | $post_link = esc_url(get_permalink()); |
| 73 | 91 | $image_src = wp_get_attachment_image_url(get_post_thumbnail_id(), 'large'); |
| 74 | 92 | $image_src = $image_src ? esc_url($image_src) : esc_url(\Elementor\Utils::get_placeholder_image_src()); |
| 75 | - $category = wp_kses_post(upk_get_category($post_type)); | |
| 93 | + $category = wp_kses_post(upk_get_category($settings['posts_source'] ?? 'post')); | |
| 76 | 94 | $author_url = esc_url(get_author_posts_url(get_the_author_meta('ID'))); |
| 77 | 95 | $author_name = esc_html(get_the_author()); |
| 78 | 96 | $title_tag = Utils::get_valid_html_tag($settings['title_tags'] ); |
| 79 | 97 | |
| 80 | - $onclick = ''; | |
| 81 | - if (!empty($settings['global_link']) && $settings['global_link'] === 'yes') { | |
| 82 | - $onclick = ' onclick="window.open(\'' . $post_link . '\', \'_self\')"'; | |
| 83 | - } | |
| 84 | - | |
| 98 | + $meta_separator = isset( $settings['meta_separator'] ) ? $settings['meta_separator'] : '|'; | |
| 99 | + | |
| 100 | + | |
| 85 | 101 | $date = ''; |
| 86 | 102 | if (!empty($settings['human_diff_time']) && $settings['human_diff_time'] === 'yes') { |
| 87 | 103 | $date = ultimate_post_kit_post_time_diff(($settings['human_diff_time_short'] === 'yes') ? 'short' : ''); |
| 88 | 104 | } else { |
| @@ -103,11 +119,11 @@ | ||
| 103 | 119 | |
| 104 | 120 | $post_format_icon = isset($format_icons[get_post_format()]) ? $format_icons[get_post_format()] : 'upk-icon-post'; |
| 105 | 121 | |
| 106 | 122 | ?> |
| 107 | - <div <?php echo $onclick; ?> class="upk-item"> | |
| 123 | + <div <?php if ( ! empty( $settings['global_link'] ) && $settings['global_link'] === 'yes' ) { printf( 'onclick="window.open(\'%s\', \'_self\')"', esc_url( $post_link ) ); } ?> class="upk-item"> | |
| 108 | 124 | <div class="upk-image-wrap"> |
| 109 | - <img class="upk-img" src="<?php echo $image_src; ?>" alt="<?php echo esc_attr($title); ?>"> | |
| 125 | + <img class="upk-img" src="<?php echo esc_url( $image_src ); ?>" alt="<?php echo esc_attr($title); ?>"> | |
| 110 | 126 | |
| 111 | 127 | <?php if ( |
| 112 | 128 | $settings['show_author'] === 'yes' || |
| 113 | 129 | $settings['show_date'] === 'yes' || |
| @@ -121,27 +137,25 @@ | ||
| 121 | 137 | |
| 122 | 138 | <div> |
| 123 | 139 | <?php if ($settings['show_author'] === 'yes') : ?> |
| 124 | 140 | <div class="upk-author-name"> |
| 125 | - <a href="<?php echo $author_url; ?>"><?php echo $author_name; ?></a> | |
| 141 | + <a href="<?php echo esc_url( $author_url ); ?>"><?php echo esc_html( $author_name ); ?></a> | |
| 126 | 142 | </div> |
| 127 | 143 | <?php endif; ?> |
| 128 | 144 | |
| 129 | 145 | <div class="upk-flex upk-flex-middle upk-date-reading-wrap"> |
| 130 | - <?php if ($settings['show_date'] === 'yes') : ?> | |
| 131 | - <div data-separator="<?php echo esc_attr($settings['meta_separator']); ?>"> | |
| 132 | - <div class="upk-date"><?php echo $date; ?></div> | |
| 133 | - <?php if ($settings['show_time'] === 'yes') : ?> | |
| 134 | - <div class="upk-post-time"> | |
| 135 | - <i class="upk-icon-clock" aria-hidden="true"></i><?php echo esc_html(get_the_time()); ?> | |
| 136 | - </div> | |
| 137 | - <?php endif; ?> | |
| 138 | - </div> | |
| 146 | + <?php if ( $settings['show_date'] === 'yes' ) : ?> | |
| 147 | + <div class="upk-date"><?php echo esc_html( $date ); ?></div> | |
| 148 | + <?php if ( $settings['show_time'] === 'yes' ) : ?> | |
| 149 | + <div class="upk-post-time" data-separator="<?php echo esc_attr( $meta_separator ); ?>"> | |
| 150 | + <i class="upk-icon-clock" aria-hidden="true"></i><?php echo esc_html( get_the_time() ); ?> | |
| 151 | + </div> | |
| 152 | + <?php endif; ?> | |
| 139 | 153 | <?php endif; ?> |
| 140 | - | |
| 141 | - <?php if (function_exists('_is_upk_pro_activated') && _is_upk_pro_activated() && $settings['show_reading_time'] === 'yes') : ?> | |
| 142 | - <div class="upk-reading-time" data-separator="<?php echo esc_attr($settings['meta_separator']); ?>"> | |
| 143 | - <?php echo ultimate_post_kit_reading_time(get_the_content(), $settings['avg_reading_speed']); ?> | |
| 154 | + | |
| 155 | + <?php if ( function_exists( '_is_upk_pro_activated' ) && _is_upk_pro_activated() && $settings['show_reading_time'] === 'yes' ) : ?> | |
| 156 | + <div class="upk-reading-time" data-separator="<?php echo esc_attr( $meta_separator ); ?>"> | |
| 157 | + <?php echo wp_kses_post( ultimate_post_kit_reading_time( get_the_content(), $settings['avg_reading_speed'], $settings['hide_seconds'] ?? 'no', $settings['hide_minutes'] ?? 'no' ) ); ?> | |
| 144 | 158 | </div> |
| 145 | 159 | <?php endif; ?> |
| 146 | 160 | </div> |
| 147 | 161 | </div> |
| @@ -149,9 +163,9 @@ | ||
| 149 | 163 | <?php endif; ?> |
| 150 | 164 | |
| 151 | 165 | <?php if ($settings['show_post_format'] === 'yes') : ?> |
| 152 | 166 | <div class="upk-post-format"> |
| 153 | - <a href="<?php echo $post_link; ?>"> | |
| 167 | + <a href="<?php echo esc_url( $post_link ); ?>"> | |
| 154 | 168 | <i class="<?php echo esc_attr($post_format_icon); ?>" aria-hidden="true"></i> |
| 155 | 169 | </a> |
| 156 | 170 | </div> |
| 157 | 171 | <?php endif; ?> |
| @@ -159,15 +173,15 @@ | ||
| 159 | 173 | |
| 160 | 174 | <div class="upk-content-wrap"> |
| 161 | 175 | <div class="upk-content"> |
| 162 | 176 | <?php if ($settings['show_category'] === 'yes') : ?> |
| 163 | - <div class="upk-category"><?php echo $category; ?></div> | |
| 177 | + <div class="upk-category"><?php echo wp_kses_post( $category ); ?></div> | |
| 164 | 178 | <?php endif; ?> |
| 165 | 179 | |
| 166 | 180 | <?php if ($settings['show_title'] === 'yes') : ?> |
| 167 | 181 | <<?php echo esc_attr( $title_tag ); ?> class="upk-title"> |
| 168 | 182 | <a class="title-animation-<?php echo esc_attr($settings['title_style']); ?>" |
| 169 | - href="<?php echo $post_link; ?>" | |
| 183 | + href="<?php echo esc_url( $post_link ); ?>" | |
| 170 | 184 | title="<?php echo esc_attr($title); ?>" |
| 171 | 185 | <?php echo $settings['upk_link_new_tab'] === 'yes' ? 'target="_blank"' : ''; ?> |
| 172 | 186 | > |
| 173 | 187 | <?php echo esc_html($title); ?> |
| @@ -177,9 +191,9 @@ | ||
| 177 | 191 | </div> |
| 178 | 192 | |
| 179 | 193 | <?php if ($settings['show_readmore'] === 'yes') : ?> |
| 180 | 194 | <div class="upk-button-wrap"> |
| 181 | - <a href="<?php echo $post_link; ?>" | |
| 195 | + <a href="<?php echo esc_url( $post_link ); ?>" | |
| 182 | 196 | class="upk-readmore" |
| 183 | 197 | target="<?php echo ($settings['upk_link_new_tab'] === 'yes') ? '_blank' : '_self'; ?>"> |
| 184 | 198 | <span class="upk-readmore-icon"><span></span></span> |
| 185 | 199 | </a> |