| @@ -158,8 +158,9 @@ | ||
| 158 | 158 | $this->add_group_control( |
| 159 | 159 | Group_Control_Image_Size::get_type(), |
| 160 | 160 | [ |
| 161 | 161 | 'name' => 'primary_thumbnail', |
| 162 | + // phpcs:ignore WordPressVIPMinimum.Performance.WPQueryParams.PostNotIn_exclude -- Elementor widget query built from user-configured controls; expected behaviour. | |
| 162 | 163 | 'exclude' => ['custom'], |
| 163 | 164 | 'default' => 'full', |
| 164 | 165 | ] |
| 165 | 166 | ); |
| @@ -278,8 +279,11 @@ | ||
| 278 | 279 | ], |
| 279 | 280 | 'default' => [ |
| 280 | 281 | 'size' => 12, |
| 281 | 282 | ], |
| 283 | + 'condition' => [ | |
| 284 | + 'posts_source!' => 'current_query', | |
| 285 | + ] | |
| 282 | 286 | ] |
| 283 | 287 | ); |
| 284 | 288 | |
| 285 | 289 | $this->register_query_builder_controls(); |
| @@ -317,10 +321,13 @@ | ||
| 317 | 321 | |
| 318 | 322 | $this->add_control( |
| 319 | 323 | 'pauseonhover', |
| 320 | 324 | [ |
| 321 | - 'label' => esc_html__('Pause on Hover', 'ultimate-post-kit'), | |
| 322 | - 'type' => Controls_Manager::SWITCHER, | |
| 325 | + 'label' => esc_html__('Pause on Hover', 'ultimate-post-kit'), | |
| 326 | + 'type' => Controls_Manager::SWITCHER, | |
| 327 | + 'condition' => [ | |
| 328 | + 'autoplay' => 'yes', | |
| 329 | + ], | |
| 323 | 330 | ] |
| 324 | 331 | ); |
| 325 | 332 | |
| 326 | 333 | $this->add_control( |
| @@ -882,9 +889,8 @@ | ||
| 882 | 889 | $default = $this->getGroupControlQueryArgs(); |
| 883 | 890 | $args = []; |
| 884 | 891 | if ($posts_per_page) { |
| 885 | 892 | $args['posts_per_page'] = $posts_per_page; |
| 886 | - // $args['paged'] = max(1, get_query_var('paged'), get_query_var('page')); | |
| 887 | 893 | } |
| 888 | 894 | $args = array_merge($default, $args); |
| 889 | 895 | $this->_query = new WP_Query($args); |
| 890 | 896 | } |
| @@ -913,9 +919,10 @@ | ||
| 913 | 919 | if (!$this->get_settings('show_title')) { |
| 914 | 920 | return; |
| 915 | 921 | } |
| 916 | 922 | |
| 917 | - printf('<%1$s class="upk-title"><a href="%2$s" title="%3$s">%3$s</a></%1$s>', esc_attr(Utils::get_valid_html_tag($settings['title_tags'])), esc_url( get_permalink() ), esc_html( get_the_title() )); | |
| 923 | + $title = get_the_title(); | |
| 924 | + printf('<%1$s class="upk-title"><a href="%2$s" title="%4$s">%3$s</a></%1$s>', esc_attr(Utils::get_valid_html_tag($settings['title_tags'])), esc_url( get_permalink() ), esc_html( $title ), esc_attr( $title )); | |
| 918 | 925 | } |
| 919 | 926 | |
| 920 | 927 | public function render_excerpt($excerpt_length) { |
| 921 | 928 | |
| @@ -928,9 +935,9 @@ | ||
| 928 | 935 | <?php |
| 929 | 936 | if (has_excerpt()) { |
| 930 | 937 | the_excerpt(); |
| 931 | 938 | } else { |
| 932 | - echo ultimate_post_kit_custom_excerpt($excerpt_length, $strip_shortcode); | |
| 939 | + echo wp_kses_post( ultimate_post_kit_custom_excerpt($excerpt_length, $strip_shortcode) ); | |
| 933 | 940 | } |
| 934 | 941 | ?> |
| 935 | 942 | </div> |
| 936 | 943 | |
| @@ -943,9 +950,9 @@ | ||
| 943 | 950 | return; |
| 944 | 951 | } |
| 945 | 952 | ?> |
| 946 | 953 | <div class="upk-category" data-swiper-parallax="-300"> |
| 947 | - <?php echo get_the_category_list(' '); ?> | |
| 954 | + <?php echo wp_kses_post( get_the_category_list(' ') ); ?> | |
| 948 | 955 | </div> |
| 949 | 956 | <?php |
| 950 | 957 | } |
| 951 | 958 | |
| @@ -996,16 +1003,14 @@ | ||
| 996 | 1003 | |
| 997 | 1004 | if (!$this->get_settings('show_comments')) { |
| 998 | 1005 | return; |
| 999 | 1006 | } |
| 1000 | - ?> | |
| 1001 | - | |
| 1007 | + | |
| 1008 | + ?> | |
| 1002 | 1009 | <div class="upk-comments"> |
| 1003 | - <?php echo get_comments_number($id) ?> | |
| 1004 | - <?php echo esc_html__('Comments', 'ultimate-post-kit') ?> | |
| 1010 | + <?php echo esc_html( Utils::get_formatted_comments_count( $id ) ); ?> | |
| 1005 | 1011 | </div> |
| 1006 | - | |
| 1007 | - <?php | |
| 1012 | + <?php | |
| 1008 | 1013 | } |
| 1009 | 1014 | |
| 1010 | 1015 | public function render_header() { |
| 1011 | 1016 | $id = 'upk-skide-slider-' . $this->get_id(); |
| @@ -1100,9 +1105,9 @@ | ||
| 1100 | 1105 | <div class="upk-date-comments"> |
| 1101 | 1106 | <?php $this->render_date(); ?> |
| 1102 | 1107 | |
| 1103 | 1108 | <?php if ($settings['show_comments']) : ?> |
| 1104 | - <div data-separator="<?php echo esc_html($settings['meta_separator']); ?>"> | |
| 1109 | + <div data-separator="<?php echo esc_attr($settings['meta_separator']); ?>"> | |
| 1105 | 1110 | <?php $this->render_comments($post_id); ?> |
| 1106 | 1111 | </div> |
| 1107 | 1112 | <?php endif; ?> |
| 1108 | 1113 | |
| @@ -1107,9 +1112,9 @@ | ||
| 1107 | 1112 | <?php endif; ?> |
| 1108 | 1113 | |
| 1109 | 1114 | <?php if (_is_upk_pro_activated()) : |
| 1110 | 1115 | if ('yes' === $settings['show_reading_time']) : ?> |
| 1111 | - <div class="upk-reading-time" data-separator="<?php echo esc_html($settings['meta_separator']); ?>"> | |
| 1116 | + <div class="upk-reading-time" data-separator="<?php echo esc_attr($settings['meta_separator']); ?>"> | |
| 1112 | 1117 | <?php echo esc_html( ultimate_post_kit_reading_time(get_the_content(), $settings['avg_reading_speed'], $settings['hide_seconds'] ?? 'no', $settings['hide_minutes'] ?? 'no') ); ?> |
| 1113 | 1118 | </div> |
| 1114 | 1119 | <?php endif; ?> |
| 1115 | 1120 | <?php endif; ?> |
| @@ -1189,8 +1194,9 @@ | ||
| 1189 | 1194 | </div> |
| 1190 | 1195 | </div> |
| 1191 | 1196 | <?php |
| 1192 | 1197 | if (_is_upk_pro_activated()) { |
| 1198 | + // phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedHooknameFound -- established hook name relied on across the plugin family; renaming would break integration. | |
| 1193 | 1199 | apply_filters('show_top_stories', $this); |
| 1194 | 1200 | } |
| 1195 | 1201 | ?> |
| 1196 | 1202 | |