| @@ -32,8 +32,14 @@ | ||
| 32 | 32 | return $widgets; |
| 33 | 33 | } |
| 34 | 34 | |
| 35 | 35 | public function callback_ajax_loadmore_posts() { |
| 36 | + // Verify the front-end nonce (sent by UltimatePostKitConfig.nonce) before | |
| 37 | + // processing this public load-more request. | |
| 38 | + if ( ! check_ajax_referer( 'upk-site', 'nonce', false ) ) { | |
| 39 | + wp_send_json_error( array( 'message' => esc_html__( 'Security check failed.', 'ultimate-post-kit' ) ), 403 ); | |
| 40 | + } | |
| 41 | + | |
| 36 | 42 | |
| 37 | 43 | $settings = []; |
| 38 | 44 | |
| 39 | 45 | if ( isset( $_POST['settings'] ) && is_array( $_POST['settings'] ) ) { |
| @@ -55,8 +61,11 @@ | ||
| 55 | 61 | ], |
| 56 | 62 | $settings |
| 57 | 63 | ); |
| 58 | 64 | |
| 65 | + // Fill display flags the request may have omitted (see trait) before the render loop reads them. | |
| 66 | + $settings = array_merge( $this->loadmore_display_defaults(), $settings ); | |
| 67 | + | |
| 59 | 68 | $ajaxposts = $this->query_args($settings); |
| 60 | 69 | |
| 61 | 70 | ob_start(); |
| 62 | 71 | $found_posts = false; |
| @@ -87,9 +96,9 @@ | ||
| 87 | 96 | </div> |
| 88 | 97 | |
| 89 | 98 | <?php if ( isset( $settings['show_category'] ) && 'yes' === $settings['show_category'] ) : ?> |
| 90 | 99 | <div class="upk-category"> |
| 91 | - <?php echo wp_kses_post( upk_get_category( $settings['post_source'] ) ); ?> | |
| 100 | + <?php echo wp_kses_post( upk_get_category( $settings['posts_source'] ?? 'post' ) ); ?> | |
| 92 | 101 | </div> |
| 93 | 102 | <?php endif; ?> |
| 94 | 103 | |
| 95 | 104 | <div class="upk-content"> |