PluginProbe
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets / 4.5.6
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets v4.5.6
4.5.6 4.5.5 4.5.4 4.2.1 4.2.2 4.2.3 4.5.0 4.5.2 4.5.3 4.2.0 4.1.18 4.1.17 4.1.16 4.1.15 4.1.14 4.1.13 4.1.12 4.1.11 4.1.10 4.1.9 4.1.8 4.0.9 4.1.0 4.1.1 4.1.2 All 148 releases
← All changes | modules/featured-list/module.php +12 -9 4.1.2 → 4.5.6 View file →
@@ -31,9 +31,15 @@
31 31 return $widgets;
32 32 }
33 33
34 34 public function callback_ajax_loadmore_posts() {
35 + // Verify the front-end nonce (sent by UltimatePostKitConfig.nonce) before
36 + // processing this public load-more request.
37 + if ( ! check_ajax_referer( 'upk-site', 'nonce', false ) ) {
38 + wp_send_json_error( array( 'message' => esc_html__( 'Security check failed.', 'ultimate-post-kit' ) ), 403 );
39 + }
35 40
41 +
36 42 $settings = [];
37 43
38 44 if ( isset( $_POST['settings'] ) && is_array( $_POST['settings'] ) ) {
39 45 $settings = map_deep( wp_unslash( $_POST['settings'] ), 'sanitize_text_field' );
@@ -54,8 +60,11 @@
54 60 ],
55 61 $settings
56 62 );
57 63
64 + // Fill display flags the request may have omitted (see trait) before the render loop reads them.
65 + $settings = array_merge( $this->loadmore_display_defaults(), $settings );
66 +
58 67 $ajaxposts = $this->query_args( $settings );
59 68
60 69 ob_start();
61 70 $found_posts = false;
@@ -75,15 +84,10 @@
75 84 $image_src = $image_src ? $image_src[0] : $placeholder;
76 85
77 86 $title_tag = Utils::get_valid_html_tag($settings['title_tags']);
78 87
79 - $onclick = '';
80 - if ( ! empty( $settings['global_link'] ) && $settings['global_link'] === 'yes' ) {
81 - $onclick = 'onclick="window.open(\'' . esc_url( $post_link ) . '\', \'_self\')"';
82 - }
83 -
84 88 ?>
85 - <div <?php echo $onclick; ?> class="upk-item">
89 + <div <?php if ( ! empty( $settings['global_link'] ) && $settings['global_link'] === 'yes' ) { printf( 'onclick="window.open(\'%s\', \'_self\')"', esc_url( $post_link ) ); } ?> class="upk-item">
86 90 <div class="upk-item-box">
87 91
88 92 <div class="upk-image-wrap">
89 93 <img class="upk-img" src="<?php echo esc_url( $image_src ); ?>" alt="<?php echo esc_attr( $title ); ?>">
@@ -123,9 +127,9 @@
123 127
124 128 if ( $categories ) {
125 129 foreach ( $categories as $category ) {
126 130 $bg_color = strToHex($category->name);
127 - echo '<a href="' . esc_url( get_category_link( $category->term_id ) ) . '"><span style="background-color:' . $bg_color . '"></span>' . esc_html( $category->name ) . '</a>';
131 + echo '<a href="' . esc_url( get_category_link( $category->term_id ) ) . '"><span style="background-color:' . esc_attr( $bg_color ) . '"></span>' . esc_html( $category->name ) . '</a>';
128 132 }
129 133 }
130 134 ?>
131 135 </div>
@@ -179,10 +183,9 @@
179 183
180 184 <?php if ( $settings['show_comments'] === 'yes' ) : ?>
181 185 <div data-separator="<?php echo esc_attr( $settings['meta_separator'] ?? '//' ); ?>">
182 186 <div class="upk-featured-comments">
183 - <?php echo get_comments_number( $post_id ); ?>
184 - <?php echo esc_html_x( 'Comments', 'Frontend', 'ultimate-post-kit' ); ?>
187 + <?php echo esc_html( $this->upk_get_formatted_comments_count( $post_id ) ); ?>
185 188 </div>
186 189 </div>
187 190 <?php endif; ?>
188 191