PluginProbe
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets / 4.5.6
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets v4.5.6
4.5.6 4.5.5 4.5.4 4.2.1 4.2.2 4.2.3 4.5.0 4.5.2 4.5.3 4.2.0 4.1.18 4.1.17 4.1.16 4.1.15 4.1.14 4.1.13 4.1.12 4.1.11 4.1.10 4.1.9 4.1.8 4.0.9 4.1.0 4.1.1 4.1.2 All 148 releases
← All changes | modules/author/widgets/author.php +7 -1 4.2.0 → 4.5.6 View file →
@@ -1409,8 +1409,9 @@
1409 1409 'orderby' => $settings['orderby'],
1410 1410 'order' => $settings['order'],
1411 1411 'role__in' => (!empty($settings['role'])) ? $settings['role'] : null,
1412 1412 'number' => $number,
1413 + // phpcs:ignore WordPressVIPMinimum.Performance.WPQueryParams.PostNotIn_exclude -- Elementor widget query built from user-configured controls; expected behaviour.
1413 1414 'exclude' => array_filter(array_map('absint', explode(',', esc_attr($settings['exclude'])))),
1414 1415 ]);
1415 1416
1416 1417 if ($min_published_posts > 0) {
@@ -1430,9 +1431,14 @@
1430 1431 } else {
1431 1432 $users = array_slice($users, 0, $item_limit);
1432 1433 }
1433 1434
1434 - $social_links = $settings['social_links'];
1435 + // Elementor stores control values verbatim, so the saved list must be checked
1436 + // against the control's own options before any value is used as a user field name.
1437 + $allowed_links = array_keys(ultimate_post_kit_user_contact_methods([], true));
1438 + $social_links = array_values(array_filter((array) $settings['social_links'], function ($link) use ($allowed_links) {
1439 + return is_string($link) && in_array($link, $allowed_links, true);
1440 + }));
1435 1441
1436 1442 ?>
1437 1443 <div class="upk-author">
1438 1444 <div class="upk-author-wrapper upk-<?php echo esc_attr($settings['layout_style']) ?>">