| @@ -179,8 +179,9 @@ | ||
| 179 | 179 | $this->add_group_control( |
| 180 | 180 | Group_Control_Image_Size::get_type(), |
| 181 | 181 | [ |
| 182 | 182 | 'name' => 'primary_thumbnail', |
| 183 | + // phpcs:ignore WordPressVIPMinimum.Performance.WPQueryParams.PostNotIn_exclude -- Elementor widget query built from user-configured controls; expected behaviour. | |
| 183 | 184 | 'exclude' => ['custom'], |
| 184 | 185 | 'default' => 'medium', |
| 185 | 186 | ] |
| 186 | 187 | ); |
| @@ -315,9 +316,9 @@ | ||
| 315 | 316 | [ |
| 316 | 317 | 'label' => esc_html__('Glassmorphism', 'ultimate-post-kit'), |
| 317 | 318 | 'type' => Controls_Manager::SWITCHER, |
| 318 | 319 | // translators: %1s: Opening anchor tag with link to MDN backdrop-filter documentation, %2s: Closing anchor tag |
| 319 | - 'description' => sprintf(__('This feature will not work in the Firefox browser untill you enable browser compatibility so please %1s look here %2s', 'ultimate-post-kit'), '<a href="https://developer.mozilla.org/en-US/docs/Web/CSS/backdrop-filter#Browser_compatibility" target="_blank">', '</a>'), | |
| 320 | + 'description' => sprintf(__('This feature will not work in the Firefox browser untill you enable browser compatibility so please %1$s look here %2$s', 'ultimate-post-kit'), '<a href="https://developer.mozilla.org/en-US/docs/Web/CSS/backdrop-filter#Browser_compatibility" target="_blank">', '</a>'), | |
| 320 | 321 | 'default' => 'yes', |
| 321 | 322 | 'condition' => [ |
| 322 | 323 | 'content_style' => '2', |
| 323 | 324 | ] |
| @@ -900,9 +901,9 @@ | ||
| 900 | 901 | $image_src = $image_src[0]; |
| 901 | 902 | } |
| 902 | 903 | |
| 903 | 904 | ?> |
| 904 | - <img class="upk-blog-image" src="<?php echo esc_url($image_src); ?>" alt="<?php echo esc_html(get_the_title()); ?>"> | |
| 905 | + <img class="upk-blog-image" src="<?php echo esc_url($image_src); ?>" alt="<?php echo esc_attr(get_the_title()); ?>"> | |
| 905 | 906 | <?php |
| 906 | 907 | } |
| 907 | 908 | |
| 908 | 909 | public function render_author() { |
| @@ -945,9 +946,9 @@ | ||
| 945 | 946 | |
| 946 | 947 | ?> |
| 947 | 948 | <div class="upk-blog-badge"> |
| 948 | 949 | <span> |
| 949 | - <?php echo upk_get_category($this->get_settings('posts_source')); ?> | |
| 950 | + <?php echo wp_kses_post( upk_get_category($this->get_settings('posts_source')) ); ?> | |
| 950 | 951 | </span> |
| 951 | 952 | </div> |
| 952 | 953 | <?php |
| 953 | 954 | } |
| @@ -959,9 +960,9 @@ | ||
| 959 | 960 | $this->render_header_attribute('hazel'); |
| 960 | 961 | |
| 961 | 962 | ?> |
| 962 | 963 | <div <?php $this->print_render_attribute_string('carousel'); ?>> |
| 963 | - <div class="upk-post-grid upk-pg-text-position-<?php echo esc_html($settings['content_position']) ?> upk-content-style-<?php echo esc_html($settings['content_style']) ?>"> | |
| 964 | + <div class="upk-post-grid upk-pg-text-position-<?php echo esc_attr($settings['content_position']) ?> upk-content-style-<?php echo esc_attr($settings['content_style']) ?>"> | |
| 964 | 965 | <div <?php $this->print_render_attribute_string('swiper'); ?>> |
| 965 | 966 | <div class="swiper-wrapper"> |
| 966 | 967 | <?php |
| 967 | 968 | } |
| @@ -994,9 +995,9 @@ | ||
| 994 | 995 | <div class="upk-meta"> |
| 995 | 996 | <?php $this->render_author(); ?> |
| 996 | 997 | |
| 997 | 998 | <?php if ($settings['show_date']) : ?> |
| 998 | - <div data-separator="<?php echo esc_html($settings['meta_separator']); ?>"> | |
| 999 | + <div data-separator="<?php echo esc_attr($settings['meta_separator']); ?>"> | |
| 999 | 1000 | <div class="upk-date"> |
| 1000 | 1001 | <i class="upk-icon-calendar" aria-hidden="true"></i><?php $this->render_date(); ?> |
| 1001 | 1002 | </div> |
| 1002 | 1003 | |
| @@ -1010,9 +1011,9 @@ | ||
| 1010 | 1011 | <?php endif; ?> |
| 1011 | 1012 | |
| 1012 | 1013 | <?php if (_is_upk_pro_activated()) : |
| 1013 | 1014 | if ('yes' === $settings['show_reading_time']) : ?> |
| 1014 | - <div class="upk-reading-time" data-separator="<?php echo esc_html($settings['meta_separator']); ?>"> | |
| 1015 | + <div class="upk-reading-time" data-separator="<?php echo esc_attr($settings['meta_separator']); ?>"> | |
| 1015 | 1016 | <?php echo esc_html( ultimate_post_kit_reading_time( get_the_content(), $settings['avg_reading_speed'], $settings['hide_seconds'] ?? 'no', $settings['hide_minutes'] ?? 'no' ) ); ?> |
| 1016 | 1017 | </div> |
| 1017 | 1018 | <?php endif; ?> |
| 1018 | 1019 | <?php endif; ?> |