| @@ -1,8 +1,12 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | |
| 3 | 3 | namespace UltimatePostKit; |
| 4 | 4 | |
| 5 | +if (!defined('ABSPATH')) { | |
| 6 | + exit; // Exit if accessed directly. | |
| 7 | +} | |
| 8 | + | |
| 5 | 9 | /** |
| 6 | 10 | * Biggopties class |
| 7 | 11 | */ |
| 8 | 12 | class Biggopties { |
| @@ -34,9 +38,9 @@ | ||
| 34 | 38 | * @return array|mixed |
| 35 | 39 | */ |
| 36 | 40 | private function get_api_biggopties_data() { |
| 37 | 41 | // API endpoint for biggopties - you can change this to your actual endpoint |
| 38 | - $api_url = 'https://api.sigmative.io/prod/store/api/biggopti/api-data-records'; | |
| 42 | + $api_url = ''; | |
| 39 | 43 | |
| 40 | 44 | $response = wp_remote_get($api_url, [ |
| 41 | 45 | 'timeout' => 30, |
| 42 | 46 | 'headers' => [ |
| @@ -199,28 +203,23 @@ | ||
| 199 | 203 | */ |
| 200 | 204 | private function render_api_biggopti($biggopti) { |
| 201 | 205 | ob_start(); |
| 202 | 206 | |
| 203 | - // Add custom CSS if provided | |
| 204 | - if (isset($biggopti->custom_css) && !empty($biggopti->custom_css)) { | |
| 205 | - echo '<style>' . wp_kses_post($biggopti->custom_css) . '</style>'; | |
| 206 | - } | |
| 207 | - | |
| 208 | 207 | // Prepare background styles |
| 209 | 208 | $background_style = ''; |
| 210 | 209 | $wrapper_classes = 'bdt-biggopti-wrapper'; |
| 211 | 210 | |
| 212 | 211 | if (isset($biggopti->background_color) && !empty($biggopti->background_color)) { |
| 213 | - $background_style .= 'background-color: ' . esc_attr($biggopti->background_color) . ';'; | |
| 212 | + $background_style .= 'background-color: ' . $biggopti->background_color . ';'; | |
| 214 | 213 | } |
| 215 | - | |
| 214 | + | |
| 216 | 215 | if (isset($biggopti->image) && !empty($biggopti->image)) { |
| 217 | - $background_style .= 'background-image: url(' . esc_url($biggopti->image) . ');'; | |
| 216 | + $background_style .= 'background-image: url(' . esc_url_raw($biggopti->image) . ');'; | |
| 218 | 217 | $wrapper_classes .= ' has-background-image'; |
| 219 | 218 | } |
| 220 | - | |
| 219 | + | |
| 221 | 220 | ?> |
| 222 | - <div class="<?php echo esc_attr($wrapper_classes); ?>" <?php echo $background_style ? 'style="' . $background_style . '"' : ''; ?>> | |
| 221 | + <div class="<?php echo esc_attr($wrapper_classes); ?>" <?php echo $background_style ? 'style="' . esc_attr($background_style) . '"' : ''; ?>> | |
| 223 | 222 | |
| 224 | 223 | |
| 225 | 224 | <?php $title = (isset($biggopti->title) && !empty($biggopti->title)) ? $biggopti->title : ''; ?> |
| 226 | 225 | |
| @@ -292,9 +291,9 @@ | ||
| 292 | 291 | /** |
| 293 | 292 | * AJAX: Build and return API biggopties HTML for dynamic injection |
| 294 | 293 | */ |
| 295 | 294 | public function ajax_fetch_api_biggopties() { |
| 296 | - $nonce = isset($_POST['_wpnonce']) ? sanitize_text_field($_POST['_wpnonce']) : ''; | |
| 295 | + $nonce = isset($_POST['_wpnonce']) ? sanitize_text_field(wp_unslash($_POST['_wpnonce'])) : ''; | |
| 297 | 296 | if (!wp_verify_nonce($nonce, 'ultimate-post-kit')) { |
| 298 | 297 | wp_send_json_error([ 'message' => 'invalid_nonce' ]); |
| 299 | 298 | } |
| 300 | 299 | |
| @@ -302,9 +301,9 @@ | ||
| 302 | 301 | wp_send_json_error([ 'message' => 'forbidden' ]); |
| 303 | 302 | } |
| 304 | 303 | |
| 305 | 304 | // Don't show biggopties on plugin/theme install and upload pages |
| 306 | - $current_url = isset($_POST['current_url']) ? sanitize_text_field($_POST['current_url']) : ''; | |
| 305 | + $current_url = isset($_POST['current_url']) ? sanitize_text_field(wp_unslash($_POST['current_url'])) : ''; | |
| 307 | 306 | |
| 308 | 307 | if (!empty($current_url)) { |
| 309 | 308 | $excluded_patterns = [ |
| 310 | 309 | 'plugin-install.php', |
| @@ -359,12 +358,12 @@ | ||
| 359 | 358 | /** |
| 360 | 359 | * Dismiss Biggopti. |
| 361 | 360 | */ |
| 362 | 361 | public function dismiss() { |
| 363 | - $nonce = (isset($_POST['_wpnonce'])) ? sanitize_text_field($_POST['_wpnonce']) : ''; | |
| 364 | - $id = (isset($_POST['id'])) ? esc_attr($_POST['id']) : ''; | |
| 365 | - $time = (isset($_POST['time'])) ? esc_attr($_POST['time']) : ''; | |
| 366 | - $meta = (isset($_POST['meta'])) ? esc_attr($_POST['meta']) : ''; | |
| 362 | + $nonce = (isset($_POST['_wpnonce'])) ? sanitize_text_field(wp_unslash($_POST['_wpnonce'])) : ''; | |
| 363 | + $id = isset($_POST['id']) ? sanitize_text_field(wp_unslash($_POST['id'])) : ''; | |
| 364 | + $time = isset($_POST['time']) ? absint(wp_unslash($_POST['time'])) : 0; | |
| 365 | + $meta = isset($_POST['meta']) ? sanitize_text_field(wp_unslash($_POST['meta'])) : ''; | |
| 367 | 366 | |
| 368 | 367 | if ( ! wp_verify_nonce($nonce, 'ultimate-post-kit') ) { |
| 369 | 368 | wp_send_json_error(); |
| 370 | 369 | } |
| @@ -383,14 +382,14 @@ | ||
| 383 | 382 | } else { |
| 384 | 383 | set_transient($id, true, $time); |
| 385 | 384 | |
| 386 | 385 | // Also store in options table for persistence |
| 387 | - $dismissals_option = get_option('bdt_biggopti_dismissals', []); | |
| 386 | + $dismissals_option = get_option('bdtupk_biggopti_dismissals', []); | |
| 388 | 387 | $dismissals_option[$id] = [ |
| 389 | 388 | 'dismissed_at' => time(), |
| 390 | 389 | 'expires_at' => time() + intval($time), |
| 391 | 390 | ]; |
| 392 | - update_option('bdt_biggopti_dismissals', $dismissals_option, false); | |
| 391 | + update_option('bdtupk_biggopti_dismissals', $dismissals_option, false); | |
| 393 | 392 | } |
| 394 | 393 | |
| 395 | 394 | wp_send_json_success(); |
| 396 | 395 | } |
| @@ -462,9 +461,9 @@ | ||
| 462 | 461 | $expired = get_transient($biggopti_id); |
| 463 | 462 | |
| 464 | 463 | // If transient not found, check options table for persistent dismissal |
| 465 | 464 | if (false === $expired || empty($expired)) { |
| 466 | - $dismissals_option = get_option('bdt_biggopti_dismissals', []); | |
| 465 | + $dismissals_option = get_option('bdtupk_biggopti_dismissals', []); | |
| 467 | 466 | if (isset($dismissals_option[$biggopti_id])) { |
| 468 | 467 | $dismissal = $dismissals_option[$biggopti_id]; |
| 469 | 468 | // Check if dismissal is still valid (not expired) |
| 470 | 469 | if (isset($dismissal['expires_at']) && time() < $dismissal['expires_at']) { |
| @@ -471,9 +470,9 @@ | ||
| 471 | 470 | $expired = true; |
| 472 | 471 | } else { |
| 473 | 472 | // Clean up expired dismissal from options |
| 474 | 473 | unset($dismissals_option[$biggopti_id]); |
| 475 | - update_option('bdt_biggopti_dismissals', $dismissals_option, false); | |
| 474 | + update_option('bdtupk_biggopti_dismissals', $dismissals_option, false); | |
| 476 | 475 | } |
| 477 | 476 | } |
| 478 | 477 | } |
| 479 | 478 | } |