PluginProbe
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets / 4.5.6
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets v4.5.6
4.5.6 4.5.5 4.5.4 4.2.1 4.2.2 4.2.3 4.5.0 4.5.2 4.5.3 4.2.0 4.1.18 4.1.17 4.1.16 4.1.15 4.1.14 4.1.13 4.1.12 4.1.11 4.1.10 4.1.9 4.1.8 4.0.9 4.1.0 4.1.1 4.1.2 All 148 releases
← All changes | admin/admin-biggopti.php +20 -21 4.1.16 → 4.5.6 View file →
@@ -1,8 +1,12 @@
1 1 <?php
2 2
3 3 namespace UltimatePostKit;
4 4
5 +if (!defined('ABSPATH')) {
6 + exit; // Exit if accessed directly.
7 +}
8 +
5 9 /**
6 10 * Biggopties class
7 11 */
8 12 class Biggopties {
@@ -34,9 +38,9 @@
34 38 * @return array|mixed
35 39 */
36 40 private function get_api_biggopties_data() {
37 41 // API endpoint for biggopties - you can change this to your actual endpoint
38 - $api_url = 'https://api.sigmative.io/prod/store/api/biggopti/api-data-records';
42 + $api_url = '';
39 43
40 44 $response = wp_remote_get($api_url, [
41 45 'timeout' => 30,
42 46 'headers' => [
@@ -199,28 +203,23 @@
199 203 */
200 204 private function render_api_biggopti($biggopti) {
201 205 ob_start();
202 206
203 - // Add custom CSS if provided
204 - if (isset($biggopti->custom_css) && !empty($biggopti->custom_css)) {
205 - echo '<style>' . wp_kses_post($biggopti->custom_css) . '</style>';
206 - }
207 -
208 207 // Prepare background styles
209 208 $background_style = '';
210 209 $wrapper_classes = 'bdt-biggopti-wrapper';
211 210
212 211 if (isset($biggopti->background_color) && !empty($biggopti->background_color)) {
213 - $background_style .= 'background-color: ' . esc_attr($biggopti->background_color) . ';';
212 + $background_style .= 'background-color: ' . $biggopti->background_color . ';';
214 213 }
215 -
214 +
216 215 if (isset($biggopti->image) && !empty($biggopti->image)) {
217 - $background_style .= 'background-image: url(' . esc_url($biggopti->image) . ');';
216 + $background_style .= 'background-image: url(' . esc_url_raw($biggopti->image) . ');';
218 217 $wrapper_classes .= ' has-background-image';
219 218 }
220 -
219 +
221 220 ?>
222 - <div class="<?php echo esc_attr($wrapper_classes); ?>" <?php echo $background_style ? 'style="' . $background_style . '"' : ''; ?>>
221 + <div class="<?php echo esc_attr($wrapper_classes); ?>" <?php echo $background_style ? 'style="' . esc_attr($background_style) . '"' : ''; ?>>
223 222
224 223
225 224 <?php $title = (isset($biggopti->title) && !empty($biggopti->title)) ? $biggopti->title : ''; ?>
226 225
@@ -292,9 +291,9 @@
292 291 /**
293 292 * AJAX: Build and return API biggopties HTML for dynamic injection
294 293 */
295 294 public function ajax_fetch_api_biggopties() {
296 - $nonce = isset($_POST['_wpnonce']) ? sanitize_text_field($_POST['_wpnonce']) : '';
295 + $nonce = isset($_POST['_wpnonce']) ? sanitize_text_field(wp_unslash($_POST['_wpnonce'])) : '';
297 296 if (!wp_verify_nonce($nonce, 'ultimate-post-kit')) {
298 297 wp_send_json_error([ 'message' => 'invalid_nonce' ]);
299 298 }
300 299
@@ -302,9 +301,9 @@
302 301 wp_send_json_error([ 'message' => 'forbidden' ]);
303 302 }
304 303
305 304 // Don't show biggopties on plugin/theme install and upload pages
306 - $current_url = isset($_POST['current_url']) ? sanitize_text_field($_POST['current_url']) : '';
305 + $current_url = isset($_POST['current_url']) ? sanitize_text_field(wp_unslash($_POST['current_url'])) : '';
307 306
308 307 if (!empty($current_url)) {
309 308 $excluded_patterns = [
310 309 'plugin-install.php',
@@ -359,12 +358,12 @@
359 358 /**
360 359 * Dismiss Biggopti.
361 360 */
362 361 public function dismiss() {
363 - $nonce = (isset($_POST['_wpnonce'])) ? sanitize_text_field($_POST['_wpnonce']) : '';
364 - $id = (isset($_POST['id'])) ? esc_attr($_POST['id']) : '';
365 - $time = (isset($_POST['time'])) ? esc_attr($_POST['time']) : '';
366 - $meta = (isset($_POST['meta'])) ? esc_attr($_POST['meta']) : '';
362 + $nonce = (isset($_POST['_wpnonce'])) ? sanitize_text_field(wp_unslash($_POST['_wpnonce'])) : '';
363 + $id = isset($_POST['id']) ? sanitize_text_field(wp_unslash($_POST['id'])) : '';
364 + $time = isset($_POST['time']) ? absint(wp_unslash($_POST['time'])) : 0;
365 + $meta = isset($_POST['meta']) ? sanitize_text_field(wp_unslash($_POST['meta'])) : '';
367 366
368 367 if ( ! wp_verify_nonce($nonce, 'ultimate-post-kit') ) {
369 368 wp_send_json_error();
370 369 }
@@ -383,14 +382,14 @@
383 382 } else {
384 383 set_transient($id, true, $time);
385 384
386 385 // Also store in options table for persistence
387 - $dismissals_option = get_option('bdt_biggopti_dismissals', []);
386 + $dismissals_option = get_option('bdtupk_biggopti_dismissals', []);
388 387 $dismissals_option[$id] = [
389 388 'dismissed_at' => time(),
390 389 'expires_at' => time() + intval($time),
391 390 ];
392 - update_option('bdt_biggopti_dismissals', $dismissals_option, false);
391 + update_option('bdtupk_biggopti_dismissals', $dismissals_option, false);
393 392 }
394 393
395 394 wp_send_json_success();
396 395 }
@@ -462,9 +461,9 @@
462 461 $expired = get_transient($biggopti_id);
463 462
464 463 // If transient not found, check options table for persistent dismissal
465 464 if (false === $expired || empty($expired)) {
466 - $dismissals_option = get_option('bdt_biggopti_dismissals', []);
465 + $dismissals_option = get_option('bdtupk_biggopti_dismissals', []);
467 466 if (isset($dismissals_option[$biggopti_id])) {
468 467 $dismissal = $dismissals_option[$biggopti_id];
469 468 // Check if dismissal is still valid (not expired)
470 469 if (isset($dismissal['expires_at']) && time() < $dismissal['expires_at']) {
@@ -471,9 +470,9 @@
471 470 $expired = true;
472 471 } else {
473 472 // Clean up expired dismissal from options
474 473 unset($dismissals_option[$biggopti_id]);
475 - update_option('bdt_biggopti_dismissals', $dismissals_option, false);
474 + update_option('bdtupk_biggopti_dismissals', $dismissals_option, false);
476 475 }
477 476 }
478 477 }
479 478 }