← All changes
|
vendor/ayecode/wp-super-duper/wp-super-duper.php
+22
-20
1.2.73
→
1.2.77
View file →
| @@ -4,9 +4,9 @@ | ||
| 4 | 4 | } |
| 5 | 5 | |
| 6 | 6 | if ( ! class_exists( 'WP_Super_Duper' ) ) { |
| 7 | 7 | |
| 8 | - define( 'SUPER_DUPER_VER', '1.2.35' ); | |
| 8 | + define( 'SUPER_DUPER_VER', '1.2.37' ); | |
| 9 | 9 | |
| 10 | 10 | /** |
| 11 | 11 | * A Class to be able to create a Widget, Shortcode or Block to be able to output content for WordPress. |
| 12 | 12 | * |
| @@ -290,34 +290,36 @@ | ||
| 290 | 290 | * |
| 291 | 291 | * @return string |
| 292 | 292 | */ |
| 293 | 293 | public static function get_picker( $editor_id = '' ) { |
| 294 | + global $sd_widgets; | |
| 294 | 295 | |
| 295 | - ob_start(); | |
| 296 | + if ( wp_doing_ajax() ) { | |
| 297 | + check_ajax_referer( 'super_duper_picker', '_ajax_nonce' ); | |
| 298 | + } | |
| 299 | + | |
| 296 | 300 | if ( isset( $_POST['editor_id'] ) ) { |
| 297 | - $editor_id = esc_attr( $_POST['editor_id'] ); | |
| 301 | + $editor_id = sanitize_text_field( wp_unslash( $_POST['editor_id'] ) ); | |
| 298 | 302 | } elseif ( isset( $_REQUEST['et_fb'] ) ) { |
| 299 | 303 | $editor_id = 'main_content_content_vb_tiny_mce'; |
| 300 | 304 | } |
| 301 | 305 | |
| 302 | - global $sd_widgets; | |
| 306 | + ksort( $sd_widgets ); | |
| 303 | 307 | |
| 304 | -// print_r($sd_widgets);exit; | |
| 308 | + ob_start(); | |
| 305 | 309 | ?> |
| 306 | - | |
| 307 | 310 | <div class="sd-shortcode-left-wrap"> |
| 308 | 311 | <?php |
| 309 | - ksort( $sd_widgets ); | |
| 310 | - // print_r($sd_widgets);exit; | |
| 311 | 312 | if ( ! empty( $sd_widgets ) ) { |
| 312 | 313 | echo '<select class="widefat" onchange="sd_get_shortcode_options(this);">'; |
| 313 | 314 | echo "<option>" . __( 'Select shortcode', 'ayecode-connect' ) . "</option>"; |
| 314 | 315 | foreach ( $sd_widgets as $shortcode => $class ) { |
| 315 | - if(!empty($class['output_types']) && !in_array('shortcode', $class['output_types'])){ continue; } | |
| 316 | - echo "<option value='" . esc_attr( $shortcode ) . "'>" . esc_attr( $shortcode ) . " (" . esc_attr( $class['name'] ) . ")</option>"; | |
| 316 | + if ( ! empty( $class['output_types'] ) && ! in_array( 'shortcode', $class['output_types'] ) ) { | |
| 317 | + continue; | |
| 318 | + } | |
| 319 | + echo "<option value='" . esc_attr( $shortcode ) . "'>" . esc_html( $shortcode ) . " (" . esc_html( $class['name'] ) . ")</option>"; | |
| 317 | 320 | } |
| 318 | 321 | echo "</select>"; |
| 319 | - | |
| 320 | 322 | } |
| 321 | 323 | ?> |
| 322 | 324 | <div class="sd-shortcode-settings"></div> |
| 323 | 325 | </div> |
| @@ -324,9 +326,9 @@ | ||
| 324 | 326 | <div class="sd-shortcode-right-wrap"> |
| 325 | 327 | <textarea id='sd-shortcode-output' disabled></textarea> |
| 326 | 328 | <div id='sd-shortcode-output-actions'> |
| 327 | 329 | <?php if ( $editor_id != '' ) { ?> |
| 328 | - <button class="button sd-insert-shortcode-button" onclick="sd_insert_shortcode(<?php if ( ! empty( $editor_id ) ) { echo "'" . $editor_id . "'"; } ?>)"><?php esc_html_e( 'Insert Shortcode', 'ayecode-connect' ); ?></button> | |
| 330 | + <button class="button sd-insert-shortcode-button" onclick="sd_insert_shortcode(<?php if ( ! empty( $editor_id ) ) { echo "'" . esc_js( $editor_id ) . "'"; } ?>)"><?php esc_html_e( 'Insert Shortcode', 'ayecode-connect' ); ?></button> | |
| 329 | 331 | <?php } ?> |
| 330 | 332 | <button class="button" onclick="sd_copy_to_clipboard()"><?php esc_html_e( 'Copy Shortcode', 'ayecode-connect' ); ?></button> |
| 331 | 333 | </div> |
| 332 | 334 | </div> |
| @@ -388,9 +390,9 @@ | ||
| 388 | 390 | */ |
| 389 | 391 | public static function get_widget_settings() { |
| 390 | 392 | global $sd_widgets; |
| 391 | 393 | |
| 392 | - $shortcode = isset( $_REQUEST['shortcode'] ) && $_REQUEST['shortcode'] ? sanitize_title_with_dashes( $_REQUEST['shortcode'] ) : ''; | |
| 394 | + $shortcode = isset( $_REQUEST['shortcode'] ) && $_REQUEST['shortcode'] ? sanitize_title_with_dashes( wp_unslash( $_REQUEST['shortcode'] ) ) : ''; | |
| 393 | 395 | if ( ! $shortcode ) { |
| 394 | 396 | wp_die(); |
| 395 | 397 | } |
| 396 | 398 | $widget_args = isset( $sd_widgets[ $shortcode ] ) ? $sd_widgets[ $shortcode ] : ''; |
| @@ -407,9 +409,9 @@ | ||
| 407 | 409 | |
| 408 | 410 | ob_start(); |
| 409 | 411 | $widget->form( array() ); |
| 410 | 412 | $form = ob_get_clean(); |
| 411 | - echo "<form id='$shortcode'>" . $form . "<div class=\"widget-control-save\"></div></form>"; | |
| 413 | + echo "<form id='" . esc_attr( $shortcode ) . "'>" . $form . "<div class=\"widget-control-save\"></div></form>"; | |
| 412 | 414 | echo "<style>" . $widget->widget_css() . "</style>"; |
| 413 | 415 | echo "<script>" . $widget->widget_js() . "</script>"; |
| 414 | 416 | ?> |
| 415 | 417 | <?php |
| @@ -5057,13 +5059,13 @@ | ||
| 5057 | 5059 | |
| 5058 | 5060 | /** |
| 5059 | 5061 | * Encode shortcodes tags. |
| 5060 | 5062 | * |
| 5063 | + * @since 1.0.28 | |
| 5064 | + * | |
| 5061 | 5065 | * @param string $content Content to search for shortcode tags. |
| 5062 | 5066 | * |
| 5063 | -*@return string Content with shortcode tags removed. | |
| 5064 | - *@since 1.0.28 | |
| 5065 | - * | |
| 5067 | + * @return string Content with shortcode tags removed. | |
| 5066 | 5068 | */ |
| 5067 | 5069 | public function encode_shortcodes( $content ) { |
| 5068 | 5070 | // Avoids existing encoded tags. |
| 5069 | 5071 | $trans = array( |
| @@ -5095,13 +5097,13 @@ | ||
| 5095 | 5097 | |
| 5096 | 5098 | /** |
| 5097 | 5099 | * Remove encoded shortcod tags. |
| 5098 | 5100 | * |
| 5101 | + * @since 1.0.28 | |
| 5102 | + * | |
| 5099 | 5103 | * @param string $content Content to search for shortcode tags. |
| 5100 | 5104 | * |
| 5101 | -*@return string Content with decoded shortcode tags. | |
| 5102 | - *@since 1.0.28 | |
| 5103 | - * | |
| 5105 | + * @return string Content with decoded shortcode tags. | |
| 5104 | 5106 | */ |
| 5105 | 5107 | public function decode_shortcodes( $content ) { |
| 5106 | 5108 | $trans = array( |
| 5107 | 5109 | '[' => '[', |