PluginProbe
Post Grid Gutenberg Blocks – PostX / 5.0.41
Post Grid Gutenberg Blocks – PostX v5.0.41
5.0.41 5.0.39 5.0.38 5.0.37 5.0.36 5.0.35 5.0.34 5.0.33 5.0.32 5.0.31 5.0.30 5.0.29 5.0.28 5.0.27 5.0.26 5.0.25 5.0.23 5.0.24 5.0.22 5.0.21 5.0.20 5.0.19 5.0.18 5.0.17 2.1.1 All 238 releases
← All changes | blocks/template/filter.php +12 -4 2.1.15.0.41 View file →
@@ -1,6 +1,14 @@
1 1 <?php
2 -defined('ABSPATH') || exit;
2 +defined( 'ABSPATH' ) || exit;
3 3
4 -$wraper_before .= '<div class="ultp-filter-wrap" data-taxtype='.$attr['filterType'].' data-blockid="'.$attr['blockId'].'" data-blockname="ultimate-post_'.$block_name.'" data-postid="'.$page_post_id.'">';
5 - $wraper_before .= ultimate_post()->filter($attr['filterText'], $attr['filterType'], $attr['filterCat'], $attr['filterTag']);
6 -$wraper_before .= '</div>';
4 +$attr['filterType'] = sanitize_html_class( $attr['filterType'] );
5 +$attr['blockId'] = sanitize_html_class( $attr['blockId'] );
6 +$allowed_html_tags = ultimate_post()->ultp_allowed_html_tags();
7 +$attr['filterText'] = isset( $attr['filterText'] ) && $attr['filterText'] ? wp_kses( $attr['filterText'], $allowed_html_tags ) : '';
8 +$attr['filterMobileText'] = isset( $attr['filterMobileText'] ) && $attr['filterMobileText'] ? esc_html( $attr['filterMobileText'] ) : '';
9 +
10 +$page_post_id = ( isset( $attr['currentPostId'] ) && $attr['currentPostId'] ) ? sanitize_html_class( $attr['currentPostId'] ) : ultimate_post()->get_page_post_id( $attr['blockId'] );
11 +$self_post_id = 'data-selfpostid="' . ( ( isset( $attr['currentPostId'] ) && $attr['currentPostId'] ) ? 'yes' : 'no' ) . '"';
12 +$wraper_before .= '<div class="ultp-filter-wrap" data-taxtype=' . $attr['filterType'] . ' data-blockid="' . $attr['blockId'] . '" data-blockname="ultimate-post_' . $block_name . '" data-postid="' . $page_post_id . '"' . $self_post_id . '>';
13 + $wraper_before .= ultimate_post()->filter_html( $attr['filterText'], $attr['filterType'], $attr['filterValue'], $attr['filterMobileText'], $attr['filterMobile'] );
14 +$wraper_before .= '</div>';