| @@ -31,9 +31,15 @@ | ||
| 31 | 31 | return $widgets; |
| 32 | 32 | } |
| 33 | 33 | |
| 34 | 34 | public function callback_ajax_loadmore_posts() { |
| 35 | + // Verify the front-end nonce (sent by UltimatePostKitConfig.nonce) before | |
| 36 | + // processing this public load-more request. | |
| 37 | + if ( ! check_ajax_referer( 'upk-site', 'nonce', false ) ) { | |
| 38 | + wp_send_json_error( array( 'message' => esc_html__( 'Security check failed.', 'ultimate-post-kit' ) ), 403 ); | |
| 39 | + } | |
| 35 | 40 | |
| 41 | + | |
| 36 | 42 | $settings = []; |
| 37 | 43 | |
| 38 | 44 | if ( isset( $_POST['settings'] ) && is_array( $_POST['settings'] ) ) { |
| 39 | 45 | $settings = map_deep( wp_unslash( $_POST['settings'] ), 'sanitize_text_field' ); |
| @@ -54,8 +60,11 @@ | ||
| 54 | 60 | ], |
| 55 | 61 | $settings |
| 56 | 62 | ); |
| 57 | 63 | |
| 64 | + // Fill display flags the request may have omitted (see trait) before the render loop reads them. | |
| 65 | + $settings = array_merge( $this->loadmore_display_defaults(), $settings ); | |
| 66 | + | |
| 58 | 67 | $ajaxposts = $this->query_args( $settings ); |
| 59 | 68 | |
| 60 | 69 | ob_start(); |
| 61 | 70 | $found_posts = false; |
| @@ -129,9 +138,9 @@ | ||
| 129 | 138 | <?php |
| 130 | 139 | if ( has_excerpt() ) { |
| 131 | 140 | the_excerpt(); |
| 132 | 141 | } else { |
| 133 | - echo esc_html( wp_trim_words( get_the_content(), $settings['excerpt_length'] ?? 15 ) ); | |
| 142 | + echo esc_html( wp_trim_words( get_the_content(), ultimate_post_kit_clamp_excerpt_length( $settings['excerpt_length'] ?? 15, 15 ) ) ); | |
| 134 | 143 | } |
| 135 | 144 | ?> |
| 136 | 145 | </div> |
| 137 | 146 | <?php endif; ?> |