PluginProbe
The WP Remote WordPress Plugin / 4.73
The WP Remote WordPress Plugin v4.73
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | plugin.php +56 -102 6.624.73 View file →
@@ -4,12 +4,10 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 6.62
8 +Version: 4.73
9 9 Network: True
10 -License: GPLv2 or later
11 -License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
12 10 */
13 11
14 12 /* Copyright 2017 WP Remote (email : support@wpremote.com)
15 13
@@ -38,14 +36,8 @@
38 36 require_once dirname( __FILE__ ) . '/wp_api.php';
39 37 require_once dirname( __FILE__ ) . '/wp_actions.php';
40 38 require_once dirname( __FILE__ ) . '/info.php';
41 39 require_once dirname( __FILE__ ) . '/account.php';
42 -require_once dirname( __FILE__ ) . '/helper.php';
43 -require_once dirname( __FILE__ ) . '/wp_file_system.php';
44 -require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
45 -
46 -require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
47 -
48 40 ##WPCACHEMODULE##
49 41
50 42
51 43 $bvsettings = new WPRWPSettings();
@@ -60,25 +52,19 @@
60 52 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
61 53 register_activation_hook(__FILE__, array($wp_action, 'activate'));
62 54 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
63 55
64 -
65 56 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
66 -add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
67 -
57 +add_action('clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
68 58 ##SOADDUNINSTALLACTION##
69 59
70 -##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
71 -
72 60 ##WPCLIMODULE##
73 -
74 61 if (is_admin()) {
75 62 require_once dirname( __FILE__ ) . '/wp_admin.php';
76 63 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
77 64 add_action('admin_init', array($wpadmin, 'initHandler'));
78 - add_filter('all_plugins', array($wpadmin, 'initWhitelabel'));
65 + add_filter('all_plugins', array($wpadmin, 'initBranding'));
79 66 add_filter('plugin_row_meta', array($wpadmin, 'hidePluginDetails'), 10, 2);
80 - add_filter('debug_information', array($wpadmin, 'handlePluginHealthInfo'), 10, 1);
81 67 if ($bvsiteinfo->isMultisite()) {
82 68 add_action('network_admin_menu', array($wpadmin, 'menu'));
83 69 } else {
84 70 add_action('admin_menu', array($wpadmin, 'menu'));
@@ -84,103 +70,82 @@
84 70 add_action('admin_menu', array($wpadmin, 'menu'));
85 71 }
86 72 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
87 73 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
88 -
89 - ##MG_AJAX_ACTIONS##
90 - ##POPUP_ON_DEACTIVATION##
91 74 add_action('admin_notices', array($wpadmin, 'activateWarning'));
92 75 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
76 + ##SOADMINMENU##
93 77 }
94 78
95 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
96 - $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
97 -}
98 79
99 -#Service active check
100 -if ($bvinfo->config != false) {
101 - add_action('wpr_remove_bv_preload_include', array($wp_action, 'removeBVPreload'));
80 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
81 + $_REQUEST = array_merge($_GET, $_POST);
102 82 }
103 83
104 -require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
105 -WPRWPPHPErrorMonitoring::init();
106 -
107 -if ($bvinfo->hasValidDBVersion()) {
108 - if ($bvinfo->isServiceActive('activity_log')) {
109 - require_once dirname( __FILE__ ) . '/wp_actlog.php';
110 - $bvconfig = $bvinfo->config;
111 - $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
112 - $actlog->init();
113 - }
114 -
115 - ##MAINTENANCEMODULE##
116 -}
117 -
118 -if (WPRHelper::getRawParam('REQUEST', 'bvplugname') == "wpremote") {
84 +if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
119 85 require_once dirname( __FILE__ ) . '/callback/base.php';
120 86 require_once dirname( __FILE__ ) . '/callback/response.php';
121 87 require_once dirname( __FILE__ ) . '/callback/request.php';
122 88 require_once dirname( __FILE__ ) . '/recover.php';
123 89
124 - $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
125 - $pubkey = isset($pubkey) ? WPRAccount::sanitizeKey($pubkey) : '';
126 - $rcvracc = WPRHelper::getRawParam('REQUEST', 'rcvracc');
90 + $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
127 91
128 - if (isset($rcvracc)) {
92 + if (array_key_exists('rcvracc', $_REQUEST)) {
129 93 $account = WPRRecover::find($bvsettings, $pubkey);
130 94 } else {
131 95 $account = WPRAccount::find($bvsettings, $pubkey);
132 96 }
133 97
134 - $request = new WPRCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
135 - $response = new WPRCallbackResponse($request->bvb64cksize);
98 + $request = new BVCallbackRequest($account, $_REQUEST);
99 + $response = new BVCallbackResponse($request->bvb64cksize);
136 100
137 - if ($request->authenticate() === 1) {
138 - $bv_frm_tstng = WPRHelper::getRawParam('REQUEST', 'bv_frm_tstng');
139 - if (isset($bv_frm_tstng)) {
140 - require_once dirname(__FILE__) . '/form_testing/form_testing.php';
141 - $form_testing = new BVFormTesting($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
142 - $form_testing->init();
101 + if ($account && (1 === $account->authenticate($request))) {
102 + define('WPRBASEPATH', plugin_dir_path(__FILE__));
143 103
144 - } else {
145 - define('WPRBASEPATH', plugin_dir_path(__FILE__));
146 104
105 + require_once dirname( __FILE__ ) . '/callback/handler.php';
147 106
148 - require_once dirname( __FILE__ ) . '/callback/handler.php';
149 -
150 - $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
151 - if ($params === false) {
152 - $response->terminate($request->corruptedParamsResp());
153 - }
154 - $request->params = $params;
155 - $callback_handler = new WPRCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
156 - if ($request->is_afterload) {
157 - add_action('wp_loaded', array($callback_handler, 'execute'));
158 - } else if ($request->is_admin_ajax) {
159 - add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
160 - add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
161 - } else {
162 - $callback_handler->execute();
163 - }
107 + $params = $request->processParams($_REQUEST);
108 + if ($params === false) {
109 + $resp = array(
110 + "account_info" => $account->info(),
111 + "request_info" => $request->info(),
112 + "bvinfo" => $bvinfo->info(),
113 + "statusmsg" => "BVPRMS_CORRUPTED"
114 + );
115 + $response->terminate($resp);
164 116 }
117 + $request->params = $params;
118 + $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
119 + if ($request->is_afterload) {
120 + add_action('wp_loaded', array($callback_handler, 'execute'));
121 + } else if ($request->is_admin_ajax) {
122 + add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
123 + add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
124 + } else {
125 + $callback_handler->execute();
126 + }
165 127 } else {
166 - $response->terminate($request->authFailedResp());
128 + $resp = array(
129 + "account_info" => $account ? $account->info() : array("error" => "ACCOUNT_NOT_FOUND"),
130 + "request_info" => $request->info(),
131 + "bvinfo" => $bvinfo->info(),
132 + "statusmsg" => "FAILED_AUTH",
133 + "api_pubkey" => substr(WPRAccount::getApiPublicKey($bvsettings), 0, 8),
134 + "def_sigmatch" => substr(WPRAccount::getSigMatch($request, WPRRecover::getDefaultSecret($bvsettings)), 0, 8)
135 + );
136 + $response->terminate($resp);
167 137 }
168 138 } else {
169 139 if ($bvinfo->hasValidDBVersion()) {
170 140 if ($bvinfo->isProtectModuleEnabled()) {
171 - require_once dirname( __FILE__ ) . '/protect/protect.php';
172 - //For backward compatibility.
173 - WPRProtect_V662::$settings = new WPRWPSettings();
174 - WPRProtect_V662::$db = new WPRWPDb();
175 - WPRProtect_V662::$info = new WPRInfo(WPRProtect_V662::$settings);
176 -
177 - add_action('wpr_clear_pt_config', array('WPRProtect_V662', 'uninstall'));
178 -
179 - if ($bvinfo->isActivePlugin()) {
180 - WPRProtect_V662::init(WPRProtect_V662::MODE_WP);
181 - }
141 + require_once dirname( __FILE__ ) . '/protect/wp/protect.php';
142 + $bvprotect = new BVProtect($bvdb, $bvsettings);
143 + $bvprotect->init();
144 + if ($bvinfo->isActivePlugin() && !(defined( 'WP_CLI' ) && WP_CLI)) {
145 + $bvprotect->run();
182 146 }
147 + }
183 148
184 149 if ($bvinfo->isDynSyncModuleEnabled()) {
185 150 require_once dirname( __FILE__ ) . '/wp_dynsync.php';
186 151 $bvconfig = $bvinfo->config;
@@ -187,9 +152,16 @@
187 152 $dynsync = new BVWPDynSync($bvdb, $bvsettings, $bvconfig['dynsync']);
188 153 $dynsync->init();
189 154 }
190 155
156 + if ($bvinfo->isServiceActive('activity_log')) {
157 + require_once dirname( __FILE__ ) . '/wp_actlog.php';
158 + $bvconfig = $bvinfo->config;
159 + $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
160 + $actlog->init();
191 161 }
162 +
163 + }
192 164 $bv_site_settings = $bvsettings->getOption('bv_site_settings');
193 165 if (isset($bv_site_settings)) {
194 166 if (isset($bv_site_settings['wp_auto_updates'])) {
195 167 $wp_auto_updates = $bv_site_settings['wp_auto_updates'];
@@ -209,23 +181,5 @@
209 181 }
210 182 }
211 183 }
212 184
213 - if (is_admin()) {
214 - add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
215 - }
216 -
217 - ##THIRDPARTYCACHINGMODULE##
218 -}
219 -
220 -if (WPRWP2FA::isEnabled($bvsettings)) {
221 - $wp_2fa = new WPRWP2FA();
222 - $wp_2fa->init();
223 -}
224 -
225 -if (!empty($bvinfo->getLPWhitelabelInfo())) {
226 - $wp_login_whitelabel = new WPRWPLoginWhitelabel();
227 - $wp_login_whitelabel->init();
228 -}
229 -
230 -add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));
231 -##PLUGIN_LOADED_MODULE##
185 +}