| @@ -1409,8 +1409,9 @@ | ||
| 1409 | 1409 | 'orderby' => $settings['orderby'], |
| 1410 | 1410 | 'order' => $settings['order'], |
| 1411 | 1411 | 'role__in' => (!empty($settings['role'])) ? $settings['role'] : null, |
| 1412 | 1412 | 'number' => $number, |
| 1413 | + // phpcs:ignore WordPressVIPMinimum.Performance.WPQueryParams.PostNotIn_exclude -- Elementor widget query built from user-configured controls; expected behaviour. | |
| 1413 | 1414 | 'exclude' => array_filter(array_map('absint', explode(',', esc_attr($settings['exclude'])))), |
| 1414 | 1415 | ]); |
| 1415 | 1416 | |
| 1416 | 1417 | if ($min_published_posts > 0) { |
| @@ -1430,9 +1431,14 @@ | ||
| 1430 | 1431 | } else { |
| 1431 | 1432 | $users = array_slice($users, 0, $item_limit); |
| 1432 | 1433 | } |
| 1433 | 1434 | |
| 1434 | - $social_links = $settings['social_links']; | |
| 1435 | + // Elementor stores control values verbatim, so the saved list must be checked | |
| 1436 | + // against the control's own options before any value is used as a user field name. | |
| 1437 | + $allowed_links = array_keys(ultimate_post_kit_user_contact_methods([], true)); | |
| 1438 | + $social_links = array_values(array_filter((array) $settings['social_links'], function ($link) use ($allowed_links) { | |
| 1439 | + return is_string($link) && in_array($link, $allowed_links, true); | |
| 1440 | + })); | |
| 1435 | 1441 | |
| 1436 | 1442 | ?> |
| 1437 | 1443 | <div class="upk-author"> |
| 1438 | 1444 | <div class="upk-author-wrapper upk-<?php echo esc_attr($settings['layout_style']) ?>"> |