PluginProbe
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets / 4.5.6
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets v4.5.6
4.5.6 4.5.5 4.5.4 4.2.1 4.2.2 4.2.3 4.5.0 4.5.2 4.5.3 4.2.0 4.1.18 4.1.17 4.1.16 4.1.15 4.1.14 4.1.13 4.1.12 4.1.11 4.1.10 4.1.9 4.1.8 4.0.9 4.1.0 4.1.1 4.1.2 All 148 releases
← All changes | modules/alex-grid/module.php +17 -39 4.5.0 → 4.5.6 View file →
@@ -51,51 +51,33 @@
51 51 if ( isset( $_POST['settings'] ) && is_array( $_POST['settings'] ) ) {
52 52 $settings = map_deep( wp_unslash( $_POST['settings'] ), 'sanitize_text_field' );
53 53 }
54 54
55 - $post_type = $settings['post_source'] ?? 'post';
56 -
57 - // Security: Enforce query limits to prevent DoS
58 - $per_page = isset( $_POST['per_page'] ) ? absint( $_POST['per_page'] ) : 6;
59 - $per_page = min( $per_page, 50 ); // Maximum 50 posts per request
60 - $offset = isset( $_POST['offset'] ) ? absint( $_POST['offset'] ) : 0;
61 - $offset = min( $offset, 1000 ); // Maximum offset of 1000
62 -
63 - // Security: Whitelist allowed post types
64 - $allowed_post_types = [ 'post', 'page' ];
65 - // phpcs:ignore WordPress.NamingConventions.PrefixAllGlobals.NonPrefixedHooknameFound -- established hook name relied on across the plugin family; renaming would break integration.
66 - $allowed_post_types = apply_filters( 'upk_alex_grid_allowed_post_types', $allowed_post_types );
67 - $post_type = in_array( $post_type, $allowed_post_types, true ) ? $post_type : 'post';
68 -
69 - // Security: Whitelist orderby values
70 - $allowed_orderby = [ 'date', 'title', 'modified', 'rand', 'comment_count', 'menu_order' ];
71 - $posts_orderby = isset( $settings['posts_orderby'] ) && in_array( $settings['posts_orderby'], $allowed_orderby, true ) ? $settings['posts_orderby'] : 'date';
72 -
73 - // Security: Whitelist order values
74 - $posts_order = isset( $settings['posts_order'] ) && in_array( strtoupper( $settings['posts_order'] ), [ 'ASC', 'DESC' ], true ) ? strtoupper( $settings['posts_order'] ) : 'DESC';
75 -
76 - $settings = array_merge(
55 + // NOTE: the request-derived values below are NOT the ones the query is built from.
56 + // query_args() is declared without parameters and re-reads $_POST['settings']
57 + // itself, so anything merged into $settings here is discarded. The query is
58 + // constrained inside query_args(): post_status is pinned to 'publish', per_page
59 + // is clamped to 1..100, and post_type is restricted to publicly visible post
60 + // types by ultimate_post_kit_sanitize_public_post_type(). The defaults are kept
61 + // only so the render loop below has the keys it expects.
62 + $settings = array_merge(
77 63 [
78 - 'posts_source' => $post_type,
79 - 'posts_orderby' => $posts_orderby,
80 - 'posts_order' => $posts_order,
64 + 'posts_source' => 'post',
65 + 'posts_orderby' => 'date',
66 + 'posts_order' => 'DESC',
81 67 'posts_ignore_sticky_posts' => 'no',
82 68 'posts_only_with_featured_image' => 'no',
83 69 'posts_select_date' => '',
84 70 'posts_exclude_by' => [],
85 71 'posts_include_by' => [],
86 - 'posts_per_page' => $per_page,
87 - 'posts_offset' => $offset,
88 72 ],
89 73 $settings
90 74 );
91 -
75 +
76 + // Fill display flags the request may have omitted (see trait) before the render loop reads them.
77 + $settings = array_merge( $this->loadmore_display_defaults(), $settings );
78 +
92 79 $ajaxposts = $this->query_args( $settings );
93 -
94 - // Security: Override post_status to ensure only published posts are shown
95 - if ( ! current_user_can( 'edit_posts' ) ) {
96 - $ajaxposts->query_vars['post_status'] = 'publish';
97 - }
98 80
99 81 ob_start();
100 82 $found_posts = false;
101 83
@@ -107,9 +89,9 @@
107 89 $title = get_the_title();
108 90 $post_link = esc_url(get_permalink());
109 91 $image_src = wp_get_attachment_image_url(get_post_thumbnail_id(), 'large');
110 92 $image_src = $image_src ? esc_url($image_src) : esc_url(\Elementor\Utils::get_placeholder_image_src());
111 - $category = wp_kses_post(upk_get_category($post_type));
93 + $category = wp_kses_post(upk_get_category($settings['posts_source'] ?? 'post'));
112 94 $author_url = esc_url(get_author_posts_url(get_the_author_meta('ID')));
113 95 $author_name = esc_html(get_the_author());
114 96 $title_tag = Utils::get_valid_html_tag($settings['title_tags'] );
115 97
@@ -114,13 +96,9 @@
114 96 $title_tag = Utils::get_valid_html_tag($settings['title_tags'] );
115 97
116 98 $meta_separator = isset( $settings['meta_separator'] ) ? $settings['meta_separator'] : '|';
117 99
118 - $onclick = '';
119 - if (!empty($settings['global_link']) && $settings['global_link'] === 'yes') {
120 - $onclick = ' onclick="window.open(\'' . $post_link . '\', \'_self\')"';
121 - }
122 -
100 +
123 101 $date = '';
124 102 if (!empty($settings['human_diff_time']) && $settings['human_diff_time'] === 'yes') {
125 103 $date = ultimate_post_kit_post_time_diff(($settings['human_diff_time_short'] === 'yes') ? 'short' : '');
126 104 } else {