PluginProbe
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP / 1.2.75
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP v1.2.75
1.2.76 1.2.75 1.2.74 1.2.73 1.2.72 1.2.71 1.2.70 1.2.69 1.2.68 1.2.67 1.2.66 1.2.65 1.2.64 1.2.63 trunk 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 All 176 releases
← All changes | vendor/ayecode/wp-super-duper/sd-functions.php +50 -11 1.2.74 → 1.2.75 View file →
@@ -2765,17 +2765,16 @@
2765 2765 *
2766 2766 * @return array
2767 2767 */
2768 2768 function sd_build_aui_styles( $args ) {
2769 -
2770 2769 $styles = array();
2771 2770
2772 2771 // background color
2773 2772 if ( ! empty( $args['bg'] ) && $args['bg'] !== '' ) {
2774 2773 if ( $args['bg'] == 'custom-color' ) {
2775 - $styles['background-color'] = $args['bg_color'];
2774 + $styles['background-color'] = sd_sanitize_css_color( $args['bg_color'] );
2776 2775 } elseif ( $args['bg'] == 'custom-gradient' ) {
2777 - $styles['background-image'] = $args['bg_gradient'];
2776 + $styles['background-image'] = sd_sanitize_css_color( $args['bg_gradient'] );
2778 2777
2779 2778 // use background on text.
2780 2779 if ( ! empty( $args['bg_on_text'] ) && $args['bg_on_text'] ) {
2781 2780 $styles['background-clip'] = 'text';
@@ -2829,9 +2828,9 @@
2829 2828 }
2830 2829
2831 2830 // font color
2832 2831 if ( ! empty( $args['text_color_custom'] ) && $args['text_color_custom'] !== '' ) {
2833 - $styles['color'] = esc_attr( $args['text_color_custom'] );
2832 + $styles['color'] = sd_sanitize_css_color( $args['text_color_custom'] );
2834 2833 }
2835 2834
2836 2835 // font line height
2837 2836 if ( ! empty( $args['font_line_height'] ) && $args['font_line_height'] !== '' ) {
@@ -2863,28 +2862,39 @@
2863 2862 * @return string
2864 2863 */
2865 2864 function sd_build_hover_styles( $args, $is_preview = false ) {
2866 2865 $rules = '';
2866 +
2867 2867 // text color
2868 2868 if ( ! empty( $args['styleid'] ) ) {
2869 - $styleid = $is_preview ? 'html .editor-styles-wrapper .' . esc_attr( $args['styleid'] ) : 'html .' . esc_attr( $args['styleid'] );
2869 + // The style id is used as a CSS class selector, so only class-safe characters may survive.
2870 + $styleid_classes = array_filter( array_map( 'sanitize_html_class', explode( ' ', (string) $args['styleid'] ) ) );
2870 2871
2871 - // text
2872 + if ( empty( $styleid_classes ) ) {
2873 + return '';
2874 + }
2875 +
2876 + $styleid_class = implode( '.', $styleid_classes );
2877 + $styleid = $is_preview ? 'html .editor-styles-wrapper .' . $styleid_class : 'html .' . $styleid_class;
2878 +
2879 + // text_color_hover
2872 2880 if ( ! empty( $args['text_color_hover'] ) ) {
2873 2881 $key = 'custom' === $args['text_color_hover'] && ! empty( $args['text_color_hover_custom'] ) ? 'text_color_hover_custom' : 'text_color_hover';
2874 - $color = sd_get_color_from_var( $args[ $key ] );
2882 + $color = sd_sanitize_css_color( $args[ $key ], 'inherit' );
2883 + $color = sd_get_color_from_var( $color );
2875 2884 $rules .= $styleid . ':hover {color: ' . $color . ' !important;} ';
2876 2885 }
2877 2886
2878 - // bg
2887 + // bg_hover
2879 2888 if ( ! empty( $args['bg_hover'] ) ) {
2880 2889 if ( 'custom-gradient' === $args['bg_hover'] ) {
2881 - $color = $args['bg_hover_gradient'];
2890 + $color = sd_sanitize_css_color( $args['bg_hover_gradient'], 'inherit' );
2882 2891 $rules .= $styleid . ':hover {background-image: ' . $color . ' !important;} ';
2883 2892 $rules .= $styleid . '.btn:hover {border-color: transparent !important;} ';
2884 2893 } else {
2885 2894 $key = 'custom-color' === $args['bg_hover'] ? 'bg_hover_color' : 'bg_hover';
2886 - $color = sd_get_color_from_var( $args[ $key ] );
2895 + $color = sd_sanitize_css_color( $args[ $key ], 'inherit' );
2896 + $color = sd_get_color_from_var( $color );
2887 2897 $rules .= $styleid . ':hover {background: ' . $color . ' !important;} ';
2888 2898 $rules .= $styleid . '.btn:hover {border-color: ' . $color . ' !important;} ';
2889 2899 }
2890 2900 }
@@ -2900,9 +2910,8 @@
2900 2910 *
2901 2911 * @return mixed|string
2902 2912 */
2903 2913 function sd_get_color_from_var( $var ) {
2904 -
2905 2914 //sanitize_hex_color() @todo this does not cover transparency
2906 2915 if ( strpos( $var, '#' ) === false ) {
2907 2916 $var = defined( 'BLOCKSTRAP_BLOCKS_VERSION' ) ? 'var(--wp--preset--color--' . esc_attr( $var ) . ')' : 'var(--' . esc_attr( $var ) . ')';
2908 2917 }
@@ -2907,8 +2916,38 @@
2907 2916 $var = defined( 'BLOCKSTRAP_BLOCKS_VERSION' ) ? 'var(--wp--preset--color--' . esc_attr( $var ) . ')' : 'var(--' . esc_attr( $var ) . ')';
2908 2917 }
2909 2918
2910 2919 return $var;
2920 +}
2921 +
2922 +/**
2923 + * Sanitizes a CSS color value.
2924 + *
2925 + * @since 1.2.37
2926 + *
2927 + * @param string $color The color value to sanitize.
2928 + * @param string $default Optional. Value to return when the color is empty or unsafe. Default empty.
2929 + * @return string Sanitized color value or default.
2930 + */
2931 +function sd_sanitize_css_color( $color, $default = '' ) {
2932 + if ( ! is_scalar( $color ) || $color === '' ) {
2933 + return $default;
2934 + }
2935 +
2936 + // Remove CSS comments, which can hide things like expression/**/( or url/**/(.
2937 + $color = preg_replace( '#/\*.*?(\*/|$)#s', '', (string) $color );
2938 +
2939 + // Keep only the part before the first ; { or }.
2940 + $color = trim( preg_split( '/[;{}]/', $color )[0] );
2941 +
2942 + // Allow trailing !important.
2943 + $value = preg_replace( '/\s*!important$/i', '', $color );
2944 +
2945 + if ( $value === '' || preg_match( '/[^\w\s#%.,()\/*+-]|url\s*\(|expression\s*\(/i', $value ) ) {
2946 + return $default;
2947 + }
2948 +
2949 + return $color;
2911 2950 }
2912 2951
2913 2952 /**
2914 2953 * Sanitize single or multiple HTML classes.