PluginProbe
The WP Remote WordPress Plugin / 4.86
The WP Remote WordPress Plugin v4.86
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | plugin.php +48 -87 6.474.86 View file →
@@ -4,12 +4,10 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 6.47
8 +Version: 4.86
9 9 Network: True
10 -License: GPLv2 or later
11 -License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
12 10 */
13 11
14 12 /* Copyright 2017 WP Remote (email : support@wpremote.com)
15 13
@@ -38,14 +36,8 @@
38 36 require_once dirname( __FILE__ ) . '/wp_api.php';
39 37 require_once dirname( __FILE__ ) . '/wp_actions.php';
40 38 require_once dirname( __FILE__ ) . '/info.php';
41 39 require_once dirname( __FILE__ ) . '/account.php';
42 -require_once dirname( __FILE__ ) . '/helper.php';
43 -require_once dirname( __FILE__ ) . '/wp_file_system.php';
44 -require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
45 -
46 -require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
47 -
48 40 ##WPCACHEMODULE##
49 41
50 42
51 43 $bvsettings = new WPRWPSettings();
@@ -60,22 +52,18 @@
60 52 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
61 53 register_activation_hook(__FILE__, array($wp_action, 'activate'));
62 54 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
63 55
64 -
65 56 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
66 -add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
67 -
57 +add_action('clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
68 58 ##SOADDUNINSTALLACTION##
69 59
70 -##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
71 -
72 60 ##WPCLIMODULE##
73 61 if (is_admin()) {
74 62 require_once dirname( __FILE__ ) . '/wp_admin.php';
75 63 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
76 64 add_action('admin_init', array($wpadmin, 'initHandler'));
77 - add_filter('all_plugins', array($wpadmin, 'initWhitelabel'));
65 + add_filter('all_plugins', array($wpadmin, 'initBranding'));
78 66 add_filter('plugin_row_meta', array($wpadmin, 'hidePluginDetails'), 10, 2);
79 67 add_filter('debug_information', array($wpadmin, 'handlePluginHealthInfo'), 10, 1);
80 68 if ($bvsiteinfo->isMultisite()) {
81 69 add_action('network_admin_menu', array($wpadmin, 'menu'));
@@ -83,11 +71,8 @@
83 71 add_action('admin_menu', array($wpadmin, 'menu'));
84 72 }
85 73 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
86 74 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
87 -
88 - ##MG_AJAX_ACTIONS##
89 - ##POPUP_ON_DEACTIVATION##
90 75 add_action('admin_notices', array($wpadmin, 'activateWarning'));
91 76 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
92 77 ##ALPURGECACHEFUNCTION##
93 78 ##ALADMINMENU##
@@ -92,20 +77,12 @@
92 77 ##ALPURGECACHEFUNCTION##
93 78 ##ALADMINMENU##
94 79 }
95 80
96 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
97 - $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
81 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
82 + $_REQUEST = array_merge($_GET, $_POST);
98 83 }
99 84
100 -#Service active check
101 -if ($bvinfo->config != false) {
102 - add_action('wpr_remove_bv_preload_include', array($wp_action, 'removeBVPreload'));
103 -}
104 -
105 -require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
106 -WPRWPPHPErrorMonitoring::init();
107 -
108 85 if ($bvinfo->hasValidDBVersion()) {
109 86 if ($bvinfo->isServiceActive('activity_log')) {
110 87 require_once dirname( __FILE__ ) . '/wp_actlog.php';
111 88 $bvconfig = $bvinfo->config;
@@ -112,76 +89,74 @@
112 89 $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
113 90 $actlog->init();
114 91 }
115 92
116 - ##MAINTENANCEMODULE##
117 93 }
118 94
119 -if (WPRHelper::getRawParam('REQUEST', 'bvplugname') == "wpremote") {
95 +if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
120 96 require_once dirname( __FILE__ ) . '/callback/base.php';
121 97 require_once dirname( __FILE__ ) . '/callback/response.php';
122 98 require_once dirname( __FILE__ ) . '/callback/request.php';
123 99 require_once dirname( __FILE__ ) . '/recover.php';
124 100
125 - $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
126 - $pubkey = isset($pubkey) ? WPRAccount::sanitizeKey($pubkey) : '';
127 - $rcvracc = WPRHelper::getRawParam('REQUEST', 'rcvracc');
101 + $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
128 102
129 - if (isset($rcvracc)) {
103 + if (array_key_exists('rcvracc', $_REQUEST)) {
130 104 $account = WPRRecover::find($bvsettings, $pubkey);
131 105 } else {
132 106 $account = WPRAccount::find($bvsettings, $pubkey);
133 107 }
134 108
135 - $request = new WPRCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
136 - $response = new WPRCallbackResponse($request->bvb64cksize);
109 + $request = new BVCallbackRequest($account, $_REQUEST);
110 + $response = new BVCallbackResponse($request->bvb64cksize);
137 111
138 - if ($request->authenticate() === 1) {
139 - $bv_frm_tstng = WPRHelper::getRawParam('REQUEST', 'bv_frm_tstng');
140 - if (isset($bv_frm_tstng)) {
141 - require_once dirname(__FILE__) . '/form_testing/form_testing.php';
142 - $form_testing = new BVFormTesting($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
143 - $form_testing->init();
112 + if ($account && (1 === $account->authenticate($request))) {
113 + define('WPRBASEPATH', plugin_dir_path(__FILE__));
144 114
145 - } else {
146 - define('WPRBASEPATH', plugin_dir_path(__FILE__));
147 115
116 + require_once dirname( __FILE__ ) . '/callback/handler.php';
148 117
149 - require_once dirname( __FILE__ ) . '/callback/handler.php';
150 -
151 - $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
152 - if ($params === false) {
153 - $response->terminate($request->corruptedParamsResp());
154 - }
155 - $request->params = $params;
156 - $callback_handler = new WPRCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
157 - if ($request->is_afterload) {
158 - add_action('wp_loaded', array($callback_handler, 'execute'));
159 - } else if ($request->is_admin_ajax) {
160 - add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
161 - add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
162 - } else {
163 - $callback_handler->execute();
164 - }
118 + $params = $request->processParams($_REQUEST);
119 + if ($params === false) {
120 + $resp = array(
121 + "account_info" => $account->info(),
122 + "request_info" => $request->info(),
123 + "bvinfo" => $bvinfo->info(),
124 + "statusmsg" => "BVPRMS_CORRUPTED"
125 + );
126 + $response->terminate($resp);
165 127 }
128 + $request->params = $params;
129 + $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
130 + if ($request->is_afterload) {
131 + add_action('wp_loaded', array($callback_handler, 'execute'));
132 + } else if ($request->is_admin_ajax) {
133 + add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
134 + add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
135 + } else {
136 + $callback_handler->execute();
137 + }
166 138 } else {
167 - $response->terminate($request->authFailedResp());
139 + $resp = array(
140 + "account_info" => $account ? $account->info() : array("error" => "ACCOUNT_NOT_FOUND"),
141 + "request_info" => $request->info(),
142 + "bvinfo" => $bvinfo->info(),
143 + "statusmsg" => "FAILED_AUTH",
144 + "api_pubkey" => substr(WPRAccount::getApiPublicKey($bvsettings), 0, 8),
145 + "def_sigmatch" => substr(WPRAccount::getSigMatch($request, WPRRecover::getDefaultSecret($bvsettings)), 0, 8)
146 + );
147 + $response->terminate($resp);
168 148 }
169 149 } else {
170 150 if ($bvinfo->hasValidDBVersion()) {
171 151 if ($bvinfo->isProtectModuleEnabled()) {
172 - require_once dirname( __FILE__ ) . '/protect/protect.php';
173 - //For backward compatibility.
174 - WPRProtect_V647::$settings = new WPRWPSettings();
175 - WPRProtect_V647::$db = new WPRWPDb();
176 - WPRProtect_V647::$info = new WPRInfo(WPRProtect_V647::$settings);
177 -
178 - add_action('wpr_clear_pt_config', array('WPRProtect_V647', 'uninstall'));
179 -
180 - if ($bvinfo->isActivePlugin()) {
181 - WPRProtect_V647::init(WPRProtect_V647::MODE_WP);
182 - }
152 + require_once dirname( __FILE__ ) . '/protect/wp/protect.php';
153 + $bvprotect = new BVProtect($bvdb, $bvsettings);
154 + $bvprotect->init();
155 + if ($bvinfo->isActivePlugin() && !(defined( 'WP_CLI' ) && WP_CLI)) {
156 + $bvprotect->run();
183 157 }
158 + }
184 159
185 160 if ($bvinfo->isDynSyncModuleEnabled()) {
186 161 require_once dirname( __FILE__ ) . '/wp_dynsync.php';
187 162 $bvconfig = $bvinfo->config;
@@ -214,19 +189,5 @@
214 189 if (is_admin()) {
215 190 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
216 191 }
217 192
218 - ##THIRDPARTYCACHINGMODULE##
219 -}
220 -
221 -if (WPRWP2FA::isEnabled($bvsettings)) {
222 - $wp_2fa = new WPRWP2FA();
223 - $wp_2fa->init();
224 -}
225 -
226 -if (!empty($bvinfo->getLPWhitelabelInfo())) {
227 - $wp_login_whitelabel = new WPRWPLoginWhitelabel();
228 - $wp_login_whitelabel->init();
229 -}
230 -
231 -add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));
232 -##PLUGIN_LOADED_MODULE##
193 +}