PluginProbe
The WP Remote WordPress Plugin / 4.68
The WP Remote WordPress Plugin v4.68
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | plugin.php +57 -130 6.694.68 View file →
@@ -4,12 +4,10 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 6.69
8 +Version: 4.68
9 9 Network: True
10 -License: GPLv2 or later
11 -License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
12 10 */
13 11
14 12 /* Copyright 2017 WP Remote (email : support@wpremote.com)
15 13
@@ -38,17 +36,10 @@
38 36 require_once dirname( __FILE__ ) . '/wp_api.php';
39 37 require_once dirname( __FILE__ ) . '/wp_actions.php';
40 38 require_once dirname( __FILE__ ) . '/info.php';
41 39 require_once dirname( __FILE__ ) . '/account.php';
42 -require_once dirname( __FILE__ ) . '/helper.php';
43 -require_once dirname( __FILE__ ) . '/wp_file_system.php';
44 -require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
45 40
46 -require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
47 41
48 -##WPCACHEMODULE##
49 -
50 -
51 42 $bvsettings = new WPRWPSettings();
52 43 $bvsiteinfo = new WPRWPSiteInfo();
53 44 $bvdb = new WPRWPDb();
54 45
@@ -60,25 +51,18 @@
60 51 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
61 52 register_activation_hook(__FILE__, array($wp_action, 'activate'));
62 53 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
63 54
64 -
65 55 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
66 -add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
56 +add_action('clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
67 57
68 -##SOADDUNINSTALLACTION##
69 -
70 -##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
71 -
72 58 ##WPCLIMODULE##
73 -
74 59 if (is_admin()) {
75 60 require_once dirname( __FILE__ ) . '/wp_admin.php';
76 61 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
77 62 add_action('admin_init', array($wpadmin, 'initHandler'));
78 - add_filter('all_plugins', array($wpadmin, 'initWhitelabel'));
63 + add_filter('all_plugins', array($wpadmin, 'initBranding'));
79 64 add_filter('plugin_row_meta', array($wpadmin, 'hidePluginDetails'), 10, 2);
80 - add_filter('debug_information', array($wpadmin, 'handlePluginHealthInfo'), 10, 1);
81 65 if ($bvsiteinfo->isMultisite()) {
82 66 add_action('network_admin_menu', array($wpadmin, 'menu'));
83 67 } else {
84 68 add_action('admin_menu', array($wpadmin, 'menu'));
@@ -84,107 +68,81 @@
84 68 add_action('admin_menu', array($wpadmin, 'menu'));
85 69 }
86 70 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
87 71 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
88 -
89 - ##MG_AJAX_ACTIONS##
90 - ##POPUP_ON_DEACTIVATION##
91 72 add_action('admin_notices', array($wpadmin, 'activateWarning'));
92 73 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
93 74 }
94 75
95 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
96 - $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
97 -}
98 76
99 -#Service active check
100 -if ($bvinfo->config != false) {
101 - add_action('wpr_remove_bv_preload_include', array($wp_action, 'removeBVPreload'));
77 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
78 + $_REQUEST = array_merge($_GET, $_POST);
102 79 }
103 80
104 -require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
105 -WPRWPPHPErrorMonitoring::init();
106 -
107 -if ($bvinfo->hasValidDBVersion()) {
108 - if ($bvinfo->isServiceActive('activity_log')) {
109 - require_once dirname( __FILE__ ) . '/wp_actlog.php';
110 - $bvconfig = $bvinfo->config;
111 - $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
112 - $actlog->init();
113 - }
114 -
115 - ##MAINTENANCEMODULE##
116 -}
117 -
118 -if (WPRHelper::getRawParam('REQUEST', 'bvplugname') == "wpremote") {
81 +if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
119 82 require_once dirname( __FILE__ ) . '/callback/base.php';
120 83 require_once dirname( __FILE__ ) . '/callback/response.php';
121 84 require_once dirname( __FILE__ ) . '/callback/request.php';
122 85 require_once dirname( __FILE__ ) . '/recover.php';
123 86
124 - $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
125 - $pubkey = isset($pubkey) ? WPRAccount::sanitizeKey($pubkey) : '';
126 - $rcvracc = WPRHelper::getRawParam('REQUEST', 'rcvracc');
87 + $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
127 88
128 - if (isset($rcvracc)) {
129 - $bvctag = WPRHelper::getRawParam('REQUEST', 'bvctag');
130 - $bvctag = isset($bvctag) ? WPRAccount::sanitizeKey($bvctag) : null;
131 - $account = WPRRecover::find($bvsettings, $pubkey, $bvctag);
89 + if (array_key_exists('rcvracc', $_REQUEST)) {
90 + $account = WPRRecover::find($bvsettings, $pubkey);
132 91 } else {
133 92 $account = WPRAccount::find($bvsettings, $pubkey);
134 93 }
135 94
136 - $request = new WPRCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
137 - $response = new WPRCallbackResponse($request->bvb64cksize);
95 + $request = new BVCallbackRequest($account, $_REQUEST);
96 + $response = new BVCallbackResponse($request->bvb64cksize);
138 97
139 - if ($request->authenticate() === 1) {
140 - $bv_frm_tstng = WPRHelper::getRawParam('REQUEST', 'bv_frm_tstng');
141 - if (isset($bv_frm_tstng)) {
142 - require_once dirname(__FILE__) . '/form_testing/form_testing.php';
143 - $form_testing = new BVFormTesting($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
144 - $form_testing->init();
98 + if ($account && (1 === $account->authenticate($request))) {
99 + define('WPRBASEPATH', plugin_dir_path(__FILE__));
145 100
146 - } else {
147 - define('WPRBASEPATH', plugin_dir_path(__FILE__));
148 101
102 + require_once dirname( __FILE__ ) . '/callback/handler.php';
149 103
150 - require_once dirname( __FILE__ ) . '/callback/handler.php';
151 -
152 - $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
153 - if ($params === false) {
154 - $response->terminate($request->corruptedParamsResp());
155 - }
156 - $request->params = $params;
157 - $callback_handler = new WPRCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
158 - if ($request->is_aftershutdown) {
159 - $callback_handler->deferExecutionUntilShutdown();
160 - } else if ($request->is_afterload) {
161 - add_action('wp_loaded', array($callback_handler, 'execute'));
162 - } else if ($request->is_admin_ajax) {
163 - add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
164 - add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
165 - } else {
166 - $callback_handler->execute();
167 - }
104 + $params = $request->processParams($_REQUEST);
105 + if ($params === false) {
106 + $resp = array(
107 + "account_info" => $account->info(),
108 + "request_info" => $request->info(),
109 + "bvinfo" => $bvinfo->info(),
110 + "statusmsg" => "BVPRMS_CORRUPTED"
111 + );
112 + $response->terminate($resp);
168 113 }
114 + $request->params = $params;
115 + $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
116 + if ($request->is_afterload) {
117 + add_action('wp_loaded', array($callback_handler, 'execute'));
118 + } else if ($request->is_admin_ajax) {
119 + add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
120 + add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
121 + } else {
122 + $callback_handler->execute();
123 + }
169 124 } else {
170 - $response->terminate($request->authFailedResp());
125 + $resp = array(
126 + "account_info" => $account ? $account->info() : array("error" => "ACCOUNT_NOT_FOUND"),
127 + "request_info" => $request->info(),
128 + "bvinfo" => $bvinfo->info(),
129 + "statusmsg" => "FAILED_AUTH",
130 + "api_pubkey" => substr(WPRAccount::getApiPublicKey($bvsettings), 0, 8),
131 + "def_sigmatch" => substr(WPRAccount::getSigMatch($request, WPRRecover::getDefaultSecret($bvsettings)), 0, 8)
132 + );
133 + $response->terminate($resp);
171 134 }
172 135 } else {
173 136 if ($bvinfo->hasValidDBVersion()) {
174 137 if ($bvinfo->isProtectModuleEnabled()) {
175 - require_once dirname( __FILE__ ) . '/protect/protect.php';
176 - //For backward compatibility.
177 - WPRProtect_V669::$settings = new WPRWPSettings();
178 - WPRProtect_V669::$db = new WPRWPDb();
179 - WPRProtect_V669::$info = new WPRInfo(WPRProtect_V669::$settings);
180 -
181 - add_action('wpr_clear_pt_config', array('WPRProtect_V669', 'uninstall'));
182 -
183 - if ($bvinfo->isActivePlugin()) {
184 - WPRProtect_V669::init(WPRProtect_V669::MODE_WP);
185 - }
138 + require_once dirname( __FILE__ ) . '/protect/wp/protect.php';
139 + $bvprotect = new BVProtect($bvdb, $bvsettings);
140 + $bvprotect->init();
141 + if ($bvinfo->isActivePlugin() && !(defined( 'WP_CLI' ) && WP_CLI)) {
142 + $bvprotect->run();
186 143 }
144 + }
187 145
188 146 if ($bvinfo->isDynSyncModuleEnabled()) {
189 147 require_once dirname( __FILE__ ) . '/wp_dynsync.php';
190 148 $bvconfig = $bvinfo->config;
@@ -191,11 +149,18 @@
191 149 $dynsync = new BVWPDynSync($bvdb, $bvsettings, $bvconfig['dynsync']);
192 150 $dynsync->init();
193 151 }
194 152
153 + if ($bvinfo->isServiceActive('activity_log')) {
154 + require_once dirname( __FILE__ ) . '/wp_actlog.php';
155 + $bvconfig = $bvinfo->config;
156 + $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
157 + $actlog->init();
195 158 }
159 +
160 + }
196 161 $bv_site_settings = $bvsettings->getOption('bv_site_settings');
197 - if (is_array($bv_site_settings)) {
162 + if (isset($bv_site_settings)) {
198 163 if (isset($bv_site_settings['wp_auto_updates'])) {
199 164 $wp_auto_updates = $bv_site_settings['wp_auto_updates'];
200 165 if (array_key_exists('block_auto_update_core', $wp_auto_updates)) {
201 166 add_filter('auto_update_core', '__return_false' );
@@ -211,45 +176,7 @@
211 176 if (array_key_exists('block_auto_update_translation', $wp_auto_updates)) {
212 177 add_filter('auto_update_translation', '__return_false' );
213 178 }
214 179 }
215 -
216 - if (isset($bv_site_settings['security_hardening'])) {
217 - $bv_security_hardening = $bv_site_settings['security_hardening'];
218 - if (is_array($bv_security_hardening) &&
219 - isset($bv_security_hardening['version']) &&
220 - $bv_security_hardening['version'] === 1) {
221 - if (isset($bv_security_hardening['disable_file_editor']) &&
222 - $bv_security_hardening['disable_file_editor'] === true &&
223 - !defined('DISALLOW_FILE_EDIT')) {
224 - define('DISALLOW_FILE_EDIT', true);
225 - }
226 -
227 - if (isset($bv_security_hardening['block_file_modifications']) &&
228 - $bv_security_hardening['block_file_modifications'] === true &&
229 - !defined('DISALLOW_FILE_MODS')) {
230 - define('DISALLOW_FILE_MODS', true);
231 - }
232 - }
233 - }
234 -
235 180 }
236 181
237 - if (is_admin()) {
238 - add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
239 - }
240 -
241 - ##THIRDPARTYCACHINGMODULE##
242 -}
243 -
244 -if (WPRWP2FA::isEnabled($bvsettings)) {
245 - $wp_2fa = new WPRWP2FA();
246 - $wp_2fa->init();
247 -}
248 -
249 -if (!empty($bvinfo->getLPWhitelabelInfo())) {
250 - $wp_login_whitelabel = new WPRWPLoginWhitelabel();
251 - $wp_login_whitelabel->init();
252 -}
253 -
254 -add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));
255 -##PLUGIN_LOADED_MODULE##
182 +}