PluginProbe
The WP Remote WordPress Plugin / 5.53
The WP Remote WordPress Plugin v5.53
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | plugin.php +35 -90 6.725.53 View file →
@@ -4,12 +4,10 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 6.72
8 +Version: 5.53
9 9 Network: True
10 -License: GPLv2 or later
11 -License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
12 10 */
13 11
14 12 /* Copyright 2017 WP Remote (email : support@wpremote.com)
15 13
@@ -39,13 +37,8 @@
39 37 require_once dirname( __FILE__ ) . '/wp_actions.php';
40 38 require_once dirname( __FILE__ ) . '/info.php';
41 39 require_once dirname( __FILE__ ) . '/account.php';
42 40 require_once dirname( __FILE__ ) . '/helper.php';
43 -require_once dirname( __FILE__ ) . '/wp_file_system.php';
44 -require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
45 -
46 -require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
47 -
48 41 ##WPCACHEMODULE##
49 42
50 43
51 44 $bvsettings = new WPRWPSettings();
@@ -60,18 +53,15 @@
60 53 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
61 54 register_activation_hook(__FILE__, array($wp_action, 'activate'));
62 55 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
63 56
64 -
65 57 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
66 -add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
67 -
58 +add_action('clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
68 59 ##SOADDUNINSTALLACTION##
69 60
70 61 ##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
71 62
72 63 ##WPCLIMODULE##
73 -
74 64 if (is_admin()) {
75 65 require_once dirname( __FILE__ ) . '/wp_admin.php';
76 66 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
77 67 add_action('admin_init', array($wpadmin, 'initHandler'));
@@ -84,27 +74,18 @@
84 74 add_action('admin_menu', array($wpadmin, 'menu'));
85 75 }
86 76 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
87 77 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
88 -
89 - ##MG_AJAX_ACTIONS##
90 - ##POPUP_ON_DEACTIVATION##
91 78 add_action('admin_notices', array($wpadmin, 'activateWarning'));
92 79 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
80 + ##ALPURGECACHEFUNCTION##
81 + ##ALADMINMENU##
93 82 }
94 83
95 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
96 - $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
84 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
85 + $_REQUEST = array_merge($_GET, $_POST);
97 86 }
98 87
99 -#Service active check
100 -if ($bvinfo->config != false) {
101 - add_action('wpr_remove_bv_preload_include', array($wp_action, 'removeBVPreload'));
102 -}
103 -
104 -require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
105 -WPRWPPHPErrorMonitoring::init();
106 -
107 88 if ($bvinfo->hasValidDBVersion()) {
108 89 if ($bvinfo->isServiceActive('activity_log')) {
109 90 require_once dirname( __FILE__ ) . '/wp_actlog.php';
110 91 $bvconfig = $bvinfo->config;
@@ -111,39 +92,44 @@
111 92 $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
112 93 $actlog->init();
113 94 }
114 95
115 - ##MAINTENANCEMODULE##
96 + if ($bvinfo->isServiceActive('maintenance_mode')) {
97 + require_once dirname( __FILE__ ). '/maintenance/wp_maintenance.php';
98 + $bvconfig = $bvinfo->config;
99 + $maintenance = new BVWPMaintenance($bvconfig['maintenance_mode']);
100 + $maintenance->init();
101 + }
102 +
116 103 }
117 104
118 -if (WPRHelper::getRawParam('REQUEST', 'bvplugname') == "wpremote") {
105 +if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
119 106 require_once dirname( __FILE__ ) . '/callback/base.php';
120 107 require_once dirname( __FILE__ ) . '/callback/response.php';
121 108 require_once dirname( __FILE__ ) . '/callback/request.php';
122 109 require_once dirname( __FILE__ ) . '/recover.php';
123 110
124 - $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
125 - $pubkey = isset($pubkey) ? WPRAccount::sanitizeKey($pubkey) : '';
126 - $rcvracc = WPRHelper::getRawParam('REQUEST', 'rcvracc');
111 + $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
127 112
128 - if (isset($rcvracc)) {
129 - $bvctag = WPRHelper::getRawParam('REQUEST', 'bvctag');
130 - $bvctag = isset($bvctag) ? WPRAccount::sanitizeKey($bvctag) : null;
131 - $account = WPRRecover::find($bvsettings, $pubkey, $bvctag);
113 + if (array_key_exists('rcvracc', $_REQUEST)) {
114 + $account = WPRRecover::find($bvsettings, $pubkey);
132 115 } else {
133 116 $account = WPRAccount::find($bvsettings, $pubkey);
134 117 }
135 118
136 - $request = new WPRCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
137 - $response = new WPRCallbackResponse($request->bvb64cksize);
119 + $request = new BVCallbackRequest($account, $_REQUEST, $bvsettings);
120 + $response = new BVCallbackResponse($request->bvb64cksize);
138 121
139 122 if ($request->authenticate() === 1) {
140 - $bv_frm_tstng = WPRHelper::getRawParam('REQUEST', 'bv_frm_tstng');
141 - if (isset($bv_frm_tstng)) {
142 - require_once dirname(__FILE__) . '/form_testing/form_testing.php';
143 - $form_testing = new BVFormTesting($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
144 - $form_testing->init();
123 + if (array_key_exists('bv_ignr_frm_cptch', $_REQUEST)) {
124 + #handling of Contact Forms 7
125 + add_filter('wpcf7_skip_spam_check', '__return_true', PHP_INT_MAX, 2);
145 126
127 + #handling of Formidable plugin
128 + add_filter('frm_is_field_hidden', '__return_true', PHP_INT_MAX, 3);
129 +
130 + #handling of WP Forms plugin
131 + add_filter('wpforms_process_bypass_captcha', '__return_true', PHP_INT_MAX, 3);
146 132 } else {
147 133 define('WPRBASEPATH', plugin_dir_path(__FILE__));
148 134
149 135
@@ -148,17 +134,15 @@
148 134
149 135
150 136 require_once dirname( __FILE__ ) . '/callback/handler.php';
151 137
152 - $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
138 + $params = $request->processParams($_REQUEST);
153 139 if ($params === false) {
154 140 $response->terminate($request->corruptedParamsResp());
155 141 }
156 142 $request->params = $params;
157 - $callback_handler = new WPRCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
158 - if ($request->is_aftershutdown) {
159 - $callback_handler->deferExecutionUntilShutdown();
160 - } else if ($request->is_afterload) {
143 + $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
144 + if ($request->is_afterload) {
161 145 add_action('wp_loaded', array($callback_handler, 'execute'));
162 146 } else if ($request->is_admin_ajax) {
163 147 add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
164 148 add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
@@ -172,17 +156,11 @@
172 156 } else {
173 157 if ($bvinfo->hasValidDBVersion()) {
174 158 if ($bvinfo->isProtectModuleEnabled()) {
175 159 require_once dirname( __FILE__ ) . '/protect/protect.php';
176 - //For backward compatibility.
177 - WPRProtect_V672::$settings = new WPRWPSettings();
178 - WPRProtect_V672::$db = new WPRWPDb();
179 - WPRProtect_V672::$info = new WPRInfo(WPRProtect_V672::$settings);
180 -
181 - add_action('wpr_clear_pt_config', array('WPRProtect_V672', 'uninstall'));
182 -
183 - if ($bvinfo->isActivePlugin()) {
184 - WPRProtect_V672::init(WPRProtect_V672::MODE_WP);
160 + add_action('clear_pt_config', array('WPRProtect_V553', 'uninstall'));
161 + if ($bvinfo->isActivePlugin() && !(defined( 'WP_CLI' ) && WP_CLI)) {
162 + WPRProtect_V553::init(WPRProtect_V553::MODE_WP);
185 163 }
186 164 }
187 165
188 166 if ($bvinfo->isDynSyncModuleEnabled()) {
@@ -193,9 +171,9 @@
193 171 }
194 172
195 173 }
196 174 $bv_site_settings = $bvsettings->getOption('bv_site_settings');
197 - if (is_array($bv_site_settings)) {
175 + if (isset($bv_site_settings)) {
198 176 if (isset($bv_site_settings['wp_auto_updates'])) {
199 177 $wp_auto_updates = $bv_site_settings['wp_auto_updates'];
200 178 if (array_key_exists('block_auto_update_core', $wp_auto_updates)) {
201 179 add_filter('auto_update_core', '__return_false' );
@@ -211,28 +189,8 @@
211 189 if (array_key_exists('block_auto_update_translation', $wp_auto_updates)) {
212 190 add_filter('auto_update_translation', '__return_false' );
213 191 }
214 192 }
215 -
216 - if (isset($bv_site_settings['security_hardening'])) {
217 - $bv_security_hardening = $bv_site_settings['security_hardening'];
218 - if (is_array($bv_security_hardening) &&
219 - isset($bv_security_hardening['version']) &&
220 - $bv_security_hardening['version'] === 1) {
221 - if (isset($bv_security_hardening['disable_file_editor']) &&
222 - $bv_security_hardening['disable_file_editor'] === true &&
223 - !defined('DISALLOW_FILE_EDIT')) {
224 - define('DISALLOW_FILE_EDIT', true);
225 - }
226 -
227 - if (isset($bv_security_hardening['block_file_modifications']) &&
228 - $bv_security_hardening['block_file_modifications'] === true &&
229 - !defined('DISALLOW_FILE_MODS')) {
230 - define('DISALLOW_FILE_MODS', true);
231 - }
232 - }
233 - }
234 -
235 193 }
236 194
237 195 if (is_admin()) {
238 196 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
@@ -238,18 +196,5 @@
238 196 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
239 197 }
240 198
241 199 ##THIRDPARTYCACHINGMODULE##
242 -}
243 -
244 -if (WPRWP2FA::isEnabled($bvsettings)) {
245 - $wp_2fa = new WPRWP2FA();
246 - $wp_2fa->init();
247 -}
248 -
249 -if (!empty($bvinfo->getLPWhitelabelInfo())) {
250 - $wp_login_whitelabel = new WPRWPLoginWhitelabel();
251 - $wp_login_whitelabel->init();
252 -}
253 -
254 -add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));
255 -##PLUGIN_LOADED_MODULE##
200 +}