| @@ -155,8 +155,9 @@ | ||
| 155 | 155 | $this->add_group_control( |
| 156 | 156 | Group_Control_Image_Size::get_type(), |
| 157 | 157 | [ |
| 158 | 158 | 'name' => 'primary_thumbnail', |
| 159 | + // phpcs:ignore WordPressVIPMinimum.Performance.WPQueryParams.PostNotIn_exclude -- Elementor widget query built from user-configured controls; expected behaviour. | |
| 159 | 160 | 'exclude' => ['custom'], |
| 160 | 161 | 'default' => 'large', |
| 161 | 162 | ] |
| 162 | 163 | ); |
| @@ -383,9 +384,9 @@ | ||
| 383 | 384 | [ |
| 384 | 385 | 'label' => esc_html__('Glassmorphism', 'ultimate-post-kit'), |
| 385 | 386 | 'type' => Controls_Manager::SWITCHER, |
| 386 | 387 | // translators: %1s: Opening anchor tag with link to MDN backdrop-filter documentation, %2s: Closing anchor tag |
| 387 | - 'description' => sprintf(__('This feature will not work in the Firefox browser untill you enable browser compatibility so please %1s look here %2s', 'ultimate-post-kit'), '<a href="https://developer.mozilla.org/en-US/docs/Web/CSS/backdrop-filter#Browser_compatibility" target="_blank">', '</a>'), | |
| 388 | + 'description' => sprintf(__('This feature will not work in the Firefox browser untill you enable browser compatibility so please %1$s look here %2$s', 'ultimate-post-kit'), '<a href="https://developer.mozilla.org/en-US/docs/Web/CSS/backdrop-filter#Browser_compatibility" target="_blank">', '</a>'), | |
| 388 | 389 | ] |
| 389 | 390 | ); |
| 390 | 391 | |
| 391 | 392 | $this->add_control( |
| @@ -1069,13 +1070,16 @@ | ||
| 1069 | 1070 | if (!$this->get_settings('show_title')) { |
| 1070 | 1071 | return; |
| 1071 | 1072 | } |
| 1072 | 1073 | |
| 1074 | + $title = get_the_title(); | |
| 1073 | 1075 | printf( |
| 1074 | - '<%1$s class="upk-title"><a data-hover="%3$s" href="%2$s" title="%3$s" class="title-animation-%4$s">%3$s</a></%1$s>', | |
| 1075 | - esc_attr(Utils::get_valid_html_tag($settings['title_tags'])), | |
| 1076 | - esc_url( get_permalink() ), esc_html( get_the_title() ), | |
| 1077 | - esc_attr($settings['title_style']) | |
| 1076 | + '<%1$s class="upk-title"><a data-hover="%5$s" href="%2$s" title="%5$s" class="title-animation-%4$s">%3$s</a></%1$s>', | |
| 1077 | + esc_attr(Utils::get_valid_html_tag($settings['title_tags'])), | |
| 1078 | + esc_url( get_permalink() ), | |
| 1079 | + esc_html( $title ), | |
| 1080 | + esc_attr($settings['title_style']), | |
| 1081 | + esc_attr( $title ) | |
| 1078 | 1082 | ); |
| 1079 | 1083 | } |
| 1080 | 1084 | |
| 1081 | 1085 | public function render_date() { |
| @@ -1096,13 +1100,13 @@ | ||
| 1096 | 1100 | <div class="upk-accordion-date"> |
| 1097 | 1101 | <i class="upk-icon-calendar" aria-hidden="true"></i> |
| 1098 | 1102 | <span <?php |
| 1099 | 1103 | if($date_for_hover){ |
| 1100 | - printf('data-hover="%s"', $date_for_hover); | |
| 1104 | + printf('data-hover="%s"', esc_attr($date_for_hover)); | |
| 1101 | 1105 | } |
| 1102 | 1106 | ?>> |
| 1103 | 1107 | <?php |
| 1104 | - echo $date_for_hover; | |
| 1108 | + echo esc_html($date_for_hover); | |
| 1105 | 1109 | ?> |
| 1106 | 1110 | </span> |
| 1107 | 1111 | </div> |
| 1108 | 1112 | <?php if ($settings['show_time']) : ?> |
| @@ -1153,9 +1157,9 @@ | ||
| 1153 | 1157 | </div> |
| 1154 | 1158 | <div class="upk-author-role"> |
| 1155 | 1159 | <?php |
| 1156 | 1160 | $aid = get_the_author_meta('ID'); |
| 1157 | - echo ucwords(get_user_role($aid)); | |
| 1161 | + echo esc_html( get_user_role( $aid ) ); | |
| 1158 | 1162 | ?> |
| 1159 | 1163 | </div> |
| 1160 | 1164 | </div> |
| 1161 | 1165 | </div> |
| @@ -1191,9 +1195,9 @@ | ||
| 1191 | 1195 | <div class="upk-accordion-meta"> |
| 1192 | 1196 | <?php $this->render_date(); ?> |
| 1193 | 1197 | |
| 1194 | 1198 | <?php if ($settings['show_comments'] == 'yes') : ?> |
| 1195 | - <div data-separator="<?php echo esc_html($settings['meta_separator']); ?>"> | |
| 1199 | + <div data-separator="<?php echo esc_attr($settings['meta_separator']); ?>"> | |
| 1196 | 1200 | <?php $this->render_comments($post_id); ?> |
| 1197 | 1201 | </div> |
| 1198 | 1202 | <?php endif; ?> |
| 1199 | 1203 | |
| @@ -1198,9 +1202,9 @@ | ||
| 1198 | 1202 | <?php endif; ?> |
| 1199 | 1203 | |
| 1200 | 1204 | <?php if (_is_upk_pro_activated()) : |
| 1201 | 1205 | if ('yes' === $settings['show_reading_time']) : ?> |
| 1202 | - <div class="upk-reading-time" data-separator="<?php echo esc_html($settings['meta_separator']); ?>"> | |
| 1206 | + <div class="upk-reading-time" data-separator="<?php echo esc_attr($settings['meta_separator']); ?>"> | |
| 1203 | 1207 | <?php echo esc_html( ultimate_post_kit_reading_time( get_the_content(), $settings['avg_reading_speed'], $settings['hide_seconds'] ?? 'no', $settings['hide_minutes'] ?? 'no' ) ); ?> |
| 1204 | 1208 | </div> |
| 1205 | 1209 | <?php endif; ?> |
| 1206 | 1210 | <?php endif; ?> |