PluginProbe
The WP Remote WordPress Plugin / 4.86
The WP Remote WordPress Plugin v4.86
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | plugin.php +52 -114 6.724.86 View file →
@@ -4,12 +4,10 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 6.72
8 +Version: 4.86
9 9 Network: True
10 -License: GPLv2 or later
11 -License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
12 10 */
13 11
14 12 /* Copyright 2017 WP Remote (email : support@wpremote.com)
15 13
@@ -38,14 +36,8 @@
38 36 require_once dirname( __FILE__ ) . '/wp_api.php';
39 37 require_once dirname( __FILE__ ) . '/wp_actions.php';
40 38 require_once dirname( __FILE__ ) . '/info.php';
41 39 require_once dirname( __FILE__ ) . '/account.php';
42 -require_once dirname( __FILE__ ) . '/helper.php';
43 -require_once dirname( __FILE__ ) . '/wp_file_system.php';
44 -require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
45 -
46 -require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
47 -
48 40 ##WPCACHEMODULE##
49 41
50 42
51 43 $bvsettings = new WPRWPSettings();
@@ -60,23 +52,18 @@
60 52 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
61 53 register_activation_hook(__FILE__, array($wp_action, 'activate'));
62 54 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
63 55
64 -
65 56 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
66 -add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
67 -
57 +add_action('clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
68 58 ##SOADDUNINSTALLACTION##
69 59
70 -##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
71 -
72 60 ##WPCLIMODULE##
73 -
74 61 if (is_admin()) {
75 62 require_once dirname( __FILE__ ) . '/wp_admin.php';
76 63 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
77 64 add_action('admin_init', array($wpadmin, 'initHandler'));
78 - add_filter('all_plugins', array($wpadmin, 'initWhitelabel'));
65 + add_filter('all_plugins', array($wpadmin, 'initBranding'));
79 66 add_filter('plugin_row_meta', array($wpadmin, 'hidePluginDetails'), 10, 2);
80 67 add_filter('debug_information', array($wpadmin, 'handlePluginHealthInfo'), 10, 1);
81 68 if ($bvsiteinfo->isMultisite()) {
82 69 add_action('network_admin_menu', array($wpadmin, 'menu'));
@@ -84,27 +71,18 @@
84 71 add_action('admin_menu', array($wpadmin, 'menu'));
85 72 }
86 73 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
87 74 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
88 -
89 - ##MG_AJAX_ACTIONS##
90 - ##POPUP_ON_DEACTIVATION##
91 75 add_action('admin_notices', array($wpadmin, 'activateWarning'));
92 76 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
77 + ##ALPURGECACHEFUNCTION##
78 + ##ALADMINMENU##
93 79 }
94 80
95 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
96 - $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
81 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
82 + $_REQUEST = array_merge($_GET, $_POST);
97 83 }
98 84
99 -#Service active check
100 -if ($bvinfo->config != false) {
101 - add_action('wpr_remove_bv_preload_include', array($wp_action, 'removeBVPreload'));
102 -}
103 -
104 -require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
105 -WPRWPPHPErrorMonitoring::init();
106 -
107 85 if ($bvinfo->hasValidDBVersion()) {
108 86 if ($bvinfo->isServiceActive('activity_log')) {
109 87 require_once dirname( __FILE__ ) . '/wp_actlog.php';
110 88 $bvconfig = $bvinfo->config;
@@ -111,80 +89,74 @@
111 89 $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
112 90 $actlog->init();
113 91 }
114 92
115 - ##MAINTENANCEMODULE##
116 93 }
117 94
118 -if (WPRHelper::getRawParam('REQUEST', 'bvplugname') == "wpremote") {
95 +if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
119 96 require_once dirname( __FILE__ ) . '/callback/base.php';
120 97 require_once dirname( __FILE__ ) . '/callback/response.php';
121 98 require_once dirname( __FILE__ ) . '/callback/request.php';
122 99 require_once dirname( __FILE__ ) . '/recover.php';
123 100
124 - $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
125 - $pubkey = isset($pubkey) ? WPRAccount::sanitizeKey($pubkey) : '';
126 - $rcvracc = WPRHelper::getRawParam('REQUEST', 'rcvracc');
101 + $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
127 102
128 - if (isset($rcvracc)) {
129 - $bvctag = WPRHelper::getRawParam('REQUEST', 'bvctag');
130 - $bvctag = isset($bvctag) ? WPRAccount::sanitizeKey($bvctag) : null;
131 - $account = WPRRecover::find($bvsettings, $pubkey, $bvctag);
103 + if (array_key_exists('rcvracc', $_REQUEST)) {
104 + $account = WPRRecover::find($bvsettings, $pubkey);
132 105 } else {
133 106 $account = WPRAccount::find($bvsettings, $pubkey);
134 107 }
135 108
136 - $request = new WPRCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
137 - $response = new WPRCallbackResponse($request->bvb64cksize);
109 + $request = new BVCallbackRequest($account, $_REQUEST);
110 + $response = new BVCallbackResponse($request->bvb64cksize);
138 111
139 - if ($request->authenticate() === 1) {
140 - $bv_frm_tstng = WPRHelper::getRawParam('REQUEST', 'bv_frm_tstng');
141 - if (isset($bv_frm_tstng)) {
142 - require_once dirname(__FILE__) . '/form_testing/form_testing.php';
143 - $form_testing = new BVFormTesting($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
144 - $form_testing->init();
112 + if ($account && (1 === $account->authenticate($request))) {
113 + define('WPRBASEPATH', plugin_dir_path(__FILE__));
145 114
146 - } else {
147 - define('WPRBASEPATH', plugin_dir_path(__FILE__));
148 115
116 + require_once dirname( __FILE__ ) . '/callback/handler.php';
149 117
150 - require_once dirname( __FILE__ ) . '/callback/handler.php';
151 -
152 - $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
153 - if ($params === false) {
154 - $response->terminate($request->corruptedParamsResp());
155 - }
156 - $request->params = $params;
157 - $callback_handler = new WPRCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
158 - if ($request->is_aftershutdown) {
159 - $callback_handler->deferExecutionUntilShutdown();
160 - } else if ($request->is_afterload) {
161 - add_action('wp_loaded', array($callback_handler, 'execute'));
162 - } else if ($request->is_admin_ajax) {
163 - add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
164 - add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
165 - } else {
166 - $callback_handler->execute();
167 - }
118 + $params = $request->processParams($_REQUEST);
119 + if ($params === false) {
120 + $resp = array(
121 + "account_info" => $account->info(),
122 + "request_info" => $request->info(),
123 + "bvinfo" => $bvinfo->info(),
124 + "statusmsg" => "BVPRMS_CORRUPTED"
125 + );
126 + $response->terminate($resp);
168 127 }
128 + $request->params = $params;
129 + $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
130 + if ($request->is_afterload) {
131 + add_action('wp_loaded', array($callback_handler, 'execute'));
132 + } else if ($request->is_admin_ajax) {
133 + add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
134 + add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
135 + } else {
136 + $callback_handler->execute();
137 + }
169 138 } else {
170 - $response->terminate($request->authFailedResp());
139 + $resp = array(
140 + "account_info" => $account ? $account->info() : array("error" => "ACCOUNT_NOT_FOUND"),
141 + "request_info" => $request->info(),
142 + "bvinfo" => $bvinfo->info(),
143 + "statusmsg" => "FAILED_AUTH",
144 + "api_pubkey" => substr(WPRAccount::getApiPublicKey($bvsettings), 0, 8),
145 + "def_sigmatch" => substr(WPRAccount::getSigMatch($request, WPRRecover::getDefaultSecret($bvsettings)), 0, 8)
146 + );
147 + $response->terminate($resp);
171 148 }
172 149 } else {
173 150 if ($bvinfo->hasValidDBVersion()) {
174 151 if ($bvinfo->isProtectModuleEnabled()) {
175 - require_once dirname( __FILE__ ) . '/protect/protect.php';
176 - //For backward compatibility.
177 - WPRProtect_V672::$settings = new WPRWPSettings();
178 - WPRProtect_V672::$db = new WPRWPDb();
179 - WPRProtect_V672::$info = new WPRInfo(WPRProtect_V672::$settings);
180 -
181 - add_action('wpr_clear_pt_config', array('WPRProtect_V672', 'uninstall'));
182 -
183 - if ($bvinfo->isActivePlugin()) {
184 - WPRProtect_V672::init(WPRProtect_V672::MODE_WP);
185 - }
152 + require_once dirname( __FILE__ ) . '/protect/wp/protect.php';
153 + $bvprotect = new BVProtect($bvdb, $bvsettings);
154 + $bvprotect->init();
155 + if ($bvinfo->isActivePlugin() && !(defined( 'WP_CLI' ) && WP_CLI)) {
156 + $bvprotect->run();
186 157 }
158 + }
187 159
188 160 if ($bvinfo->isDynSyncModuleEnabled()) {
189 161 require_once dirname( __FILE__ ) . '/wp_dynsync.php';
190 162 $bvconfig = $bvinfo->config;
@@ -193,9 +165,9 @@
193 165 }
194 166
195 167 }
196 168 $bv_site_settings = $bvsettings->getOption('bv_site_settings');
197 - if (is_array($bv_site_settings)) {
169 + if (isset($bv_site_settings)) {
198 170 if (isset($bv_site_settings['wp_auto_updates'])) {
199 171 $wp_auto_updates = $bv_site_settings['wp_auto_updates'];
200 172 if (array_key_exists('block_auto_update_core', $wp_auto_updates)) {
201 173 add_filter('auto_update_core', '__return_false' );
@@ -211,28 +183,8 @@
211 183 if (array_key_exists('block_auto_update_translation', $wp_auto_updates)) {
212 184 add_filter('auto_update_translation', '__return_false' );
213 185 }
214 186 }
215 -
216 - if (isset($bv_site_settings['security_hardening'])) {
217 - $bv_security_hardening = $bv_site_settings['security_hardening'];
218 - if (is_array($bv_security_hardening) &&
219 - isset($bv_security_hardening['version']) &&
220 - $bv_security_hardening['version'] === 1) {
221 - if (isset($bv_security_hardening['disable_file_editor']) &&
222 - $bv_security_hardening['disable_file_editor'] === true &&
223 - !defined('DISALLOW_FILE_EDIT')) {
224 - define('DISALLOW_FILE_EDIT', true);
225 - }
226 -
227 - if (isset($bv_security_hardening['block_file_modifications']) &&
228 - $bv_security_hardening['block_file_modifications'] === true &&
229 - !defined('DISALLOW_FILE_MODS')) {
230 - define('DISALLOW_FILE_MODS', true);
231 - }
232 - }
233 - }
234 -
235 187 }
236 188
237 189 if (is_admin()) {
238 190 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
@@ -237,19 +189,5 @@
237 189 if (is_admin()) {
238 190 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
239 191 }
240 192
241 - ##THIRDPARTYCACHINGMODULE##
242 -}
243 -
244 -if (WPRWP2FA::isEnabled($bvsettings)) {
245 - $wp_2fa = new WPRWP2FA();
246 - $wp_2fa->init();
247 -}
248 -
249 -if (!empty($bvinfo->getLPWhitelabelInfo())) {
250 - $wp_login_whitelabel = new WPRWPLoginWhitelabel();
251 - $wp_login_whitelabel->init();
252 -}
253 -
254 -add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));
255 -##PLUGIN_LOADED_MODULE##
193 +}