PluginProbe
The WP Remote WordPress Plugin / 4.84
The WP Remote WordPress Plugin v4.84
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | plugin.php +48 -92 6.474.84 View file →
@@ -4,12 +4,10 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 6.47
8 +Version: 4.84
9 9 Network: True
10 -License: GPLv2 or later
11 -License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
12 10 */
13 11
14 12 /* Copyright 2017 WP Remote (email : support@wpremote.com)
15 13
@@ -38,14 +36,8 @@
38 36 require_once dirname( __FILE__ ) . '/wp_api.php';
39 37 require_once dirname( __FILE__ ) . '/wp_actions.php';
40 38 require_once dirname( __FILE__ ) . '/info.php';
41 39 require_once dirname( __FILE__ ) . '/account.php';
42 -require_once dirname( __FILE__ ) . '/helper.php';
43 -require_once dirname( __FILE__ ) . '/wp_file_system.php';
44 -require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
45 -
46 -require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
47 -
48 40 ##WPCACHEMODULE##
49 41
50 42
51 43 $bvsettings = new WPRWPSettings();
@@ -60,24 +52,19 @@
60 52 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
61 53 register_activation_hook(__FILE__, array($wp_action, 'activate'));
62 54 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
63 55
64 -
65 56 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
66 -add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
67 -
57 +add_action('clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
68 58 ##SOADDUNINSTALLACTION##
69 59
70 -##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
71 -
72 60 ##WPCLIMODULE##
73 61 if (is_admin()) {
74 62 require_once dirname( __FILE__ ) . '/wp_admin.php';
75 63 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
76 64 add_action('admin_init', array($wpadmin, 'initHandler'));
77 - add_filter('all_plugins', array($wpadmin, 'initWhitelabel'));
65 + add_filter('all_plugins', array($wpadmin, 'initBranding'));
78 66 add_filter('plugin_row_meta', array($wpadmin, 'hidePluginDetails'), 10, 2);
79 - add_filter('debug_information', array($wpadmin, 'handlePluginHealthInfo'), 10, 1);
80 67 if ($bvsiteinfo->isMultisite()) {
81 68 add_action('network_admin_menu', array($wpadmin, 'menu'));
82 69 } else {
83 70 add_action('admin_menu', array($wpadmin, 'menu'));
@@ -83,11 +70,8 @@
83 70 add_action('admin_menu', array($wpadmin, 'menu'));
84 71 }
85 72 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
86 73 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
87 -
88 - ##MG_AJAX_ACTIONS##
89 - ##POPUP_ON_DEACTIVATION##
90 74 add_action('admin_notices', array($wpadmin, 'activateWarning'));
91 75 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
92 76 ##ALPURGECACHEFUNCTION##
93 77 ##ALADMINMENU##
@@ -92,20 +76,12 @@
92 76 ##ALPURGECACHEFUNCTION##
93 77 ##ALADMINMENU##
94 78 }
95 79
96 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
97 - $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
80 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
81 + $_REQUEST = array_merge($_GET, $_POST);
98 82 }
99 83
100 -#Service active check
101 -if ($bvinfo->config != false) {
102 - add_action('wpr_remove_bv_preload_include', array($wp_action, 'removeBVPreload'));
103 -}
104 -
105 -require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
106 -WPRWPPHPErrorMonitoring::init();
107 -
108 84 if ($bvinfo->hasValidDBVersion()) {
109 85 if ($bvinfo->isServiceActive('activity_log')) {
110 86 require_once dirname( __FILE__ ) . '/wp_actlog.php';
111 87 $bvconfig = $bvinfo->config;
@@ -112,76 +88,74 @@
112 88 $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
113 89 $actlog->init();
114 90 }
115 91
116 - ##MAINTENANCEMODULE##
117 92 }
118 93
119 -if (WPRHelper::getRawParam('REQUEST', 'bvplugname') == "wpremote") {
94 +if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
120 95 require_once dirname( __FILE__ ) . '/callback/base.php';
121 96 require_once dirname( __FILE__ ) . '/callback/response.php';
122 97 require_once dirname( __FILE__ ) . '/callback/request.php';
123 98 require_once dirname( __FILE__ ) . '/recover.php';
124 99
125 - $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
126 - $pubkey = isset($pubkey) ? WPRAccount::sanitizeKey($pubkey) : '';
127 - $rcvracc = WPRHelper::getRawParam('REQUEST', 'rcvracc');
100 + $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
128 101
129 - if (isset($rcvracc)) {
102 + if (array_key_exists('rcvracc', $_REQUEST)) {
130 103 $account = WPRRecover::find($bvsettings, $pubkey);
131 104 } else {
132 105 $account = WPRAccount::find($bvsettings, $pubkey);
133 106 }
134 107
135 - $request = new WPRCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
136 - $response = new WPRCallbackResponse($request->bvb64cksize);
108 + $request = new BVCallbackRequest($account, $_REQUEST);
109 + $response = new BVCallbackResponse($request->bvb64cksize);
137 110
138 - if ($request->authenticate() === 1) {
139 - $bv_frm_tstng = WPRHelper::getRawParam('REQUEST', 'bv_frm_tstng');
140 - if (isset($bv_frm_tstng)) {
141 - require_once dirname(__FILE__) . '/form_testing/form_testing.php';
142 - $form_testing = new BVFormTesting($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
143 - $form_testing->init();
111 + if ($account && (1 === $account->authenticate($request))) {
112 + define('WPRBASEPATH', plugin_dir_path(__FILE__));
144 113
145 - } else {
146 - define('WPRBASEPATH', plugin_dir_path(__FILE__));
147 114
115 + require_once dirname( __FILE__ ) . '/callback/handler.php';
148 116
149 - require_once dirname( __FILE__ ) . '/callback/handler.php';
150 -
151 - $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
152 - if ($params === false) {
153 - $response->terminate($request->corruptedParamsResp());
154 - }
155 - $request->params = $params;
156 - $callback_handler = new WPRCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
157 - if ($request->is_afterload) {
158 - add_action('wp_loaded', array($callback_handler, 'execute'));
159 - } else if ($request->is_admin_ajax) {
160 - add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
161 - add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
162 - } else {
163 - $callback_handler->execute();
164 - }
117 + $params = $request->processParams($_REQUEST);
118 + if ($params === false) {
119 + $resp = array(
120 + "account_info" => $account->info(),
121 + "request_info" => $request->info(),
122 + "bvinfo" => $bvinfo->info(),
123 + "statusmsg" => "BVPRMS_CORRUPTED"
124 + );
125 + $response->terminate($resp);
165 126 }
127 + $request->params = $params;
128 + $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
129 + if ($request->is_afterload) {
130 + add_action('wp_loaded', array($callback_handler, 'execute'));
131 + } else if ($request->is_admin_ajax) {
132 + add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
133 + add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
134 + } else {
135 + $callback_handler->execute();
136 + }
166 137 } else {
167 - $response->terminate($request->authFailedResp());
138 + $resp = array(
139 + "account_info" => $account ? $account->info() : array("error" => "ACCOUNT_NOT_FOUND"),
140 + "request_info" => $request->info(),
141 + "bvinfo" => $bvinfo->info(),
142 + "statusmsg" => "FAILED_AUTH",
143 + "api_pubkey" => substr(WPRAccount::getApiPublicKey($bvsettings), 0, 8),
144 + "def_sigmatch" => substr(WPRAccount::getSigMatch($request, WPRRecover::getDefaultSecret($bvsettings)), 0, 8)
145 + );
146 + $response->terminate($resp);
168 147 }
169 148 } else {
170 149 if ($bvinfo->hasValidDBVersion()) {
171 150 if ($bvinfo->isProtectModuleEnabled()) {
172 - require_once dirname( __FILE__ ) . '/protect/protect.php';
173 - //For backward compatibility.
174 - WPRProtect_V647::$settings = new WPRWPSettings();
175 - WPRProtect_V647::$db = new WPRWPDb();
176 - WPRProtect_V647::$info = new WPRInfo(WPRProtect_V647::$settings);
177 -
178 - add_action('wpr_clear_pt_config', array('WPRProtect_V647', 'uninstall'));
179 -
180 - if ($bvinfo->isActivePlugin()) {
181 - WPRProtect_V647::init(WPRProtect_V647::MODE_WP);
182 - }
151 + require_once dirname( __FILE__ ) . '/protect/wp/protect.php';
152 + $bvprotect = new BVProtect($bvdb, $bvsettings);
153 + $bvprotect->init();
154 + if ($bvinfo->isActivePlugin() && !(defined( 'WP_CLI' ) && WP_CLI)) {
155 + $bvprotect->run();
183 156 }
157 + }
184 158
185 159 if ($bvinfo->isDynSyncModuleEnabled()) {
186 160 require_once dirname( __FILE__ ) . '/wp_dynsync.php';
187 161 $bvconfig = $bvinfo->config;
@@ -210,23 +184,5 @@
210 184 }
211 185 }
212 186 }
213 187
214 - if (is_admin()) {
215 - add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
216 - }
217 -
218 - ##THIRDPARTYCACHINGMODULE##
219 -}
220 -
221 -if (WPRWP2FA::isEnabled($bvsettings)) {
222 - $wp_2fa = new WPRWP2FA();
223 - $wp_2fa->init();
224 -}
225 -
226 -if (!empty($bvinfo->getLPWhitelabelInfo())) {
227 - $wp_login_whitelabel = new WPRWPLoginWhitelabel();
228 - $wp_login_whitelabel->init();
229 -}
230 -
231 -add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));
232 -##PLUGIN_LOADED_MODULE##
188 +}