PluginProbe
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets / 4.5.6
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets v4.5.6
4.5.6 4.5.5 4.5.4 4.2.1 4.2.2 4.2.3 4.5.0 4.5.2 4.5.3 4.2.0 4.1.18 4.1.17 4.1.16 4.1.15 4.1.14 4.1.13 4.1.12 4.1.11 4.1.10 4.1.9 4.1.8 4.0.9 4.1.0 4.1.1 4.1.2 All 148 releases
← All changes | includes/feedback-hub/notice.php +27 -21 4.1.16 → 4.5.6 View file →
@@ -3,10 +3,10 @@
3 3 if (!defined('ABSPATH')) {
4 4 exit;
5 5 }
6 6
7 -if (!class_exists('RC_Reviews_Collector')) {
8 - class RC_Reviews_Collector {
7 +if (!class_exists('Ultimate_Post_Kit_Reviews_Collector')) {
8 + class Ultimate_Post_Kit_Reviews_Collector {
9 9
10 10 public $version = '1.0.0';
11 11
12 12 public $rc_name;
@@ -41,10 +41,10 @@
41 41 $this->params = $params;
42 42 $this->review_url = isset($params['review_url']) ? $params['review_url'] : false;
43 43
44 44 // add_action( 'admin_enqueue_scripts', array( $this, 'rc_enqueue_scripts' ) );
45 - add_action('wp_ajax_rc_sdk_insights', array($this, 'rc_sdk_insights'));
46 - add_action('wp_ajax_rc_sdk_dismiss_notice', array($this, 'rc_sdk_dismiss_notice'));
45 + add_action('wp_ajax_ultimate_post_kit_reviews_insights', array($this, 'rc_sdk_insights'));
46 + add_action('wp_ajax_ultimate_post_kit_reviews_dismiss_notice', array($this, 'rc_sdk_dismiss_notice'));
47 47
48 48 $security_key = md5($params['plugin_name']);
49 49 $this->rc_name = 'rc_' . str_replace('-', '_', sanitize_title($params['plugin_name']) . '_' . $security_key);
50 50 $this->rc_allow_name = 'rc_allow_' . $this->rc_name;
@@ -159,13 +159,22 @@
159 159 /**
160 160 * Ajax callback
161 161 */
162 162 public function rc_sdk_insights() {
163 - $sanitized_status = isset($_POST['button_val']) ? sanitize_text_field($_POST['button_val']) : '';
164 - $nonce = isset($_POST['nonce']) ? sanitize_text_field($_POST['nonce']) : '';
165 - $allow_name = isset($_POST['allow_name']) ? sanitize_text_field($_POST['allow_name']) : '';
166 - $date_name = isset($_POST['date_name']) ? sanitize_text_field($_POST['date_name']) : '';
163 + $sanitized_status = isset($_POST['button_val']) ? sanitize_text_field(wp_unslash($_POST['button_val'])) : '';
164 + $nonce = isset($_POST['nonce']) ? sanitize_text_field(wp_unslash($_POST['nonce'])) : '';
165 + $allow_name = isset($_POST['allow_name']) ? sanitize_text_field(wp_unslash($_POST['allow_name'])) : '';
166 + $date_name = isset($_POST['date_name']) ? sanitize_text_field(wp_unslash($_POST['date_name'])) : '';
167 167
168 + // Confine the writes to this SDK's own option namespace so a request
169 + // cannot use these to overwrite an arbitrary WordPress option.
170 + if (0 !== strpos($allow_name, 'rc_allow_')) {
171 + $allow_name = '';
172 + }
173 + if (0 !== strpos($date_name, 'rc_date_')) {
174 + $date_name = '';
175 + }
176 +
168 177 if (!wp_verify_nonce($nonce, 'rc_sdk')) {
169 178 wp_send_json(array(
170 179 'status' => 'error',
171 180 'title' => 'Error',
@@ -182,19 +191,21 @@
182 191 ));
183 192 wp_die();
184 193 }
185 194
186 - if ('disallow' == $sanitized_status) {
195 + if ('disallow' == $sanitized_status && $allow_name) {
187 196 update_option($allow_name, 'disallow');
188 197 }
189 198
190 - if ($sanitized_status == 'skip') {
199 + if ($sanitized_status == 'skip' && $allow_name) {
191 200 update_option($allow_name, 'skip');
192 201 /**
193 202 * Next schedule date for attempt
194 203 */
195 - update_option($date_name, gmdate('Y-m-d', strtotime("+1 month")));
196 - } elseif ($sanitized_status == 'yes') {
204 + if ($date_name) {
205 + update_option($date_name, gmdate('Y-m-d', strtotime("+1 month")));
206 + }
207 + } elseif ($sanitized_status == 'yes' && $allow_name) {
197 208 update_option($allow_name, 'yes');
198 209 }
199 210
200 211 wp_send_json(array(
@@ -268,10 +279,10 @@
268 279 *
269 280 * @return void
270 281 */
271 282 public function rc_sdk_dismiss_notice() {
272 - $nonce = isset($_POST['nonce']) ? sanitize_text_field($_POST['nonce']) : '';
273 - $rc_name = isset($_POST['rc_name']) ? sanitize_text_field($_POST['rc_name']) : '';
283 + $nonce = isset($_POST['nonce']) ? sanitize_text_field(wp_unslash($_POST['nonce'])) : '';
284 + $rc_name = isset($_POST['rc_name']) ? sanitize_text_field(wp_unslash($_POST['rc_name'])) : '';
274 285
275 286 if (!wp_verify_nonce($nonce, 'rc_sdk')) {
276 287 wp_send_json(array(
277 288 'status' => 'error',
@@ -304,12 +315,7 @@
304 315
305 316 /**
306 317 * Main Insights Function
307 318 */
308 -if (!function_exists('rc_sdk_automate')) {
309 - function rc_sdk_automate($params) {
310 - if (class_exists('RC_Reviews_Collector')) {
311 - // RC_Reviews_Collector::get_instance( $params );
312 - new RC_Reviews_Collector($params);
313 - }
314 - }
319 +function ultimate_post_kit_reviews_automate($params) {
320 + new Ultimate_Post_Kit_Reviews_Collector($params);
315 321 }