← All changes
|
includes/controls/select-input/dynamic-select-input-module.php
+15
-2
4.5.3
→
4.5.6
View file →
| @@ -95,10 +95,17 @@ | ||
| 95 | 95 | /** |
| 96 | 96 | * @return array|mixed |
| 97 | 97 | */ |
| 98 | 98 | protected function getselecedIds() { |
| 99 | - // phpcs:ignore WordPress.Security.NonceVerification.Missing -- nonce verified in getSelectInputData() before this helper runs. | |
| 100 | - return isset($_POST['ids']) ? sanitize_text_field(wp_unslash($_POST['ids'])) : []; | |
| 99 | + if ( ! check_ajax_referer( 'upk_dynamic_select', 'security', false ) ) { | |
| 100 | + return []; | |
| 101 | + } | |
| 102 | + | |
| 103 | + if ( ! isset( $_POST['ids'] ) ) { | |
| 104 | + return []; | |
| 105 | + } | |
| 106 | + | |
| 107 | + return array_values( array_filter( wp_parse_id_list( (array) wp_unslash( $_POST['ids'] ) ) ) ); | |
| 101 | 108 | } |
| 102 | 109 | |
| 103 | 110 | |
| 104 | 111 | /** |
| @@ -211,12 +218,18 @@ | ||
| 211 | 218 | $search_text = $this->getSearchQuery(); |
| 212 | 219 | $taxonomies = $this->getAllPublicTaxonomies(); |
| 213 | 220 | $include = $this->getselecedIds(); |
| 214 | 221 | |
| 222 | + $post_type = ''; | |
| 223 | + | |
| 215 | 224 | if ($this->getPostType() == '_ultimate_post_kit_pro_related_post_type') { |
| 216 | 225 | $post_type = $this->getAllPublicPostTypes(); |
| 217 | 226 | } elseif ($this->getPostType()) { |
| 218 | 227 | $post_type = $this->getPostType(); |
| 228 | + } | |
| 229 | + | |
| 230 | + if (empty($post_type)) { | |
| 231 | + return []; | |
| 219 | 232 | } |
| 220 | 233 | |
| 221 | 234 | $post_taxonomies = get_object_taxonomies($post_type); |
| 222 | 235 | $taxonomies = array_intersect($post_taxonomies, $taxonomies); |