| @@ -443,9 +443,9 @@ | ||
| 443 | 443 | [ |
| 444 | 444 | 'label' => esc_html__('Glassmorphism', 'ultimate-post-kit'), |
| 445 | 445 | 'type' => Controls_Manager::SWITCHER, |
| 446 | 446 | // translators: %1s: Opening anchor tag with link to MDN backdrop-filter documentation, %2s: Closing anchor tag |
| 447 | - 'description' => sprintf(__('This feature will not work in the Firefox browser untill you enable browser compatibility so please %1s look here %2s', 'ultimate-post-kit'), '<a href="https://developer.mozilla.org/en-US/docs/Web/CSS/backdrop-filter#Browser_compatibility" target="_blank">', '</a>'), | |
| 447 | + 'description' => sprintf(__('This feature will not work in the Firefox browser untill you enable browser compatibility so please %1$s look here %2$s', 'ultimate-post-kit'), '<a href="https://developer.mozilla.org/en-US/docs/Web/CSS/backdrop-filter#Browser_compatibility" target="_blank">', '</a>'), | |
| 448 | 448 | |
| 449 | 449 | ] |
| 450 | 450 | ); |
| 451 | 451 | |
| @@ -1409,8 +1409,9 @@ | ||
| 1409 | 1409 | 'orderby' => $settings['orderby'], |
| 1410 | 1410 | 'order' => $settings['order'], |
| 1411 | 1411 | 'role__in' => (!empty($settings['role'])) ? $settings['role'] : null, |
| 1412 | 1412 | 'number' => $number, |
| 1413 | + // phpcs:ignore WordPressVIPMinimum.Performance.WPQueryParams.PostNotIn_exclude -- Elementor widget query built from user-configured controls; expected behaviour. | |
| 1413 | 1414 | 'exclude' => array_filter(array_map('absint', explode(',', esc_attr($settings['exclude'])))), |
| 1414 | 1415 | ]); |
| 1415 | 1416 | |
| 1416 | 1417 | if ($min_published_posts > 0) { |
| @@ -1430,13 +1431,18 @@ | ||
| 1430 | 1431 | } else { |
| 1431 | 1432 | $users = array_slice($users, 0, $item_limit); |
| 1432 | 1433 | } |
| 1433 | 1434 | |
| 1434 | - $social_links = $settings['social_links']; | |
| 1435 | + // Elementor stores control values verbatim, so the saved list must be checked | |
| 1436 | + // against the control's own options before any value is used as a user field name. | |
| 1437 | + $allowed_links = array_keys(ultimate_post_kit_user_contact_methods([], true)); | |
| 1438 | + $social_links = array_values(array_filter((array) $settings['social_links'], function ($link) use ($allowed_links) { | |
| 1439 | + return is_string($link) && in_array($link, $allowed_links, true); | |
| 1440 | + })); | |
| 1435 | 1441 | |
| 1436 | 1442 | ?> |
| 1437 | 1443 | <div class="upk-author"> |
| 1438 | - <div class="upk-author-wrapper upk-<?php echo esc_html($settings['layout_style']) ?>"> | |
| 1444 | + <div class="upk-author-wrapper upk-<?php echo esc_attr($settings['layout_style']) ?>"> | |
| 1439 | 1445 | <?php |
| 1440 | 1446 | foreach ($users as $author) { |
| 1441 | 1447 | |
| 1442 | 1448 | ?> |
| @@ -1453,10 +1459,10 @@ | ||
| 1453 | 1459 | |
| 1454 | 1460 | <div class="upk-content"> |
| 1455 | 1461 | <?php if ($settings['show_author_name']) : ?> |
| 1456 | 1462 | <div class="upk-name"> |
| 1457 | - <a href="<?php echo get_bloginfo('url') . "/?author=" . esc_attr($author->ID); ?>"> | |
| 1458 | - <?php echo get_the_author_meta('display_name', $author->ID); ?> | |
| 1463 | + <a href="<?php echo esc_url(get_author_posts_url($author->ID)); ?>"> | |
| 1464 | + <?php echo esc_html(get_the_author_meta('display_name', $author->ID)); ?> | |
| 1459 | 1465 | </a> |
| 1460 | 1466 | </div> |
| 1461 | 1467 | <?php endif; ?> |
| 1462 | 1468 | |
| @@ -1461,15 +1467,15 @@ | ||
| 1461 | 1467 | <?php endif; ?> |
| 1462 | 1468 | |
| 1463 | 1469 | <?php if ($settings['show_author_role']) : ?> |
| 1464 | 1470 | <div class="upk-role"> |
| 1465 | - <?php echo ucwords(get_user_role($author->ID)); ?> | |
| 1471 | + <?php echo esc_html( get_user_role( $author->ID ) ); ?> | |
| 1466 | 1472 | </div> |
| 1467 | 1473 | <?php endif; ?> |
| 1468 | 1474 | |
| 1469 | 1475 | <?php if ($settings['show_author_description'] and get_the_author_meta('description', $author->ID)) : ?> |
| 1470 | 1476 | <div class="upk-description"> |
| 1471 | - <?php echo get_the_author_meta('description', $author->ID); ?> | |
| 1477 | + <?php echo wp_kses_post(get_the_author_meta('description', $author->ID)); ?> | |
| 1472 | 1478 | </div> |
| 1473 | 1479 | <?php endif; ?> |
| 1474 | 1480 | |
| 1475 | 1481 | <?php if ($settings['show_author_link'] and !empty($social_links)) : ?> |
| @@ -1491,9 +1497,9 @@ | ||
| 1491 | 1497 | } |
| 1492 | 1498 | |
| 1493 | 1499 | ?> |
| 1494 | 1500 | |
| 1495 | - <a href="<?php echo esc_url($final_url); ?>" title="<?php echo esc_html($alt_title); ?>"> | |
| 1501 | + <a href="<?php echo esc_url($final_url); ?>" title="<?php echo esc_attr($alt_title); ?>"> | |
| 1496 | 1502 | <i class="upk-icon-<?php echo esc_attr($link); ?>" aria-hidden="true"></i> |
| 1497 | 1503 | </a> |
| 1498 | 1504 | <?php endif; ?> |
| 1499 | 1505 | |