PluginProbe
The WP Remote WordPress Plugin / 5.88
The WP Remote WordPress Plugin v5.88
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | plugin.php +170 -46 5.095.88 View file →
@@ -4,10 +4,12 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 5.09
8 +Version: 5.88
9 9 Network: True
10 +License: GPLv2 or later
11 +License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
10 12 */
11 13
12 14 /* Copyright 2017 WP Remote (email : support@wpremote.com)
13 15
@@ -37,8 +39,12 @@
37 39 require_once dirname( __FILE__ ) . '/wp_actions.php';
38 40 require_once dirname( __FILE__ ) . '/info.php';
39 41 require_once dirname( __FILE__ ) . '/account.php';
40 42 require_once dirname( __FILE__ ) . '/helper.php';
43 +require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
44 +
45 +require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
46 +
41 47 ##WPCACHEMODULE##
42 48
43 49
44 50 $bvsettings = new WPRWPSettings();
@@ -53,10 +59,12 @@
53 59 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
54 60 register_activation_hook(__FILE__, array($wp_action, 'activate'));
55 61 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
56 62
63 +
57 64 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
58 -add_action('clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
65 +add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
66 +
59 67 ##SOADDUNINSTALLACTION##
60 68
61 69 ##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
62 70
@@ -64,9 +72,9 @@
64 72 if (is_admin()) {
65 73 require_once dirname( __FILE__ ) . '/wp_admin.php';
66 74 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
67 75 add_action('admin_init', array($wpadmin, 'initHandler'));
68 - add_filter('all_plugins', array($wpadmin, 'initBranding'));
76 + add_filter('all_plugins', array($wpadmin, 'initWhitelabel'));
69 77 add_filter('plugin_row_meta', array($wpadmin, 'hidePluginDetails'), 10, 2);
70 78 add_filter('debug_information', array($wpadmin, 'handlePluginHealthInfo'), 10, 1);
71 79 if ($bvsiteinfo->isMultisite()) {
72 80 add_action('network_admin_menu', array($wpadmin, 'menu'));
@@ -74,8 +82,9 @@
74 82 add_action('admin_menu', array($wpadmin, 'menu'));
75 83 }
76 84 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
77 85 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
86 + ##POPUP_ON_DEACTIVATION##
78 87 add_action('admin_notices', array($wpadmin, 'activateWarning'));
79 88 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
80 89 ##ALPURGECACHEFUNCTION##
81 90 ##ALADMINMENU##
@@ -80,12 +89,20 @@
80 89 ##ALPURGECACHEFUNCTION##
81 90 ##ALADMINMENU##
82 91 }
83 92
84 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
85 - $_REQUEST = array_merge($_GET, $_POST);
93 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
94 + $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
86 95 }
87 96
97 +#Service active check
98 +if ($bvinfo->config != false) {
99 + add_action('wpr_remove_bv_preload_include', array($wp_action, 'removeBVPreload'));
100 +}
101 +
102 +require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
103 +WPRWPPHPErrorMonitoring::init();
104 +
88 105 if ($bvinfo->hasValidDBVersion()) {
89 106 if ($bvinfo->isServiceActive('activity_log')) {
90 107 require_once dirname( __FILE__ ) . '/wp_actlog.php';
91 108 $bvconfig = $bvinfo->config;
@@ -92,74 +109,168 @@
92 109 $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
93 110 $actlog->init();
94 111 }
95 112
113 + if ($bvinfo->isServiceActive('maintenance_mode')) {
114 + require_once dirname( __FILE__ ). '/maintenance/wp_maintenance.php';
115 + $bvconfig = $bvinfo->config;
116 + $maintenance = new BVWPMaintenance($bvconfig['maintenance_mode']);
117 + $maintenance->init();
118 + }
119 +
96 120 }
97 121
98 -if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
122 +if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
99 123 require_once dirname( __FILE__ ) . '/callback/base.php';
100 124 require_once dirname( __FILE__ ) . '/callback/response.php';
101 125 require_once dirname( __FILE__ ) . '/callback/request.php';
102 126 require_once dirname( __FILE__ ) . '/recover.php';
103 127
104 - $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
128 + // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized, WordPress.Security.NonceVerification.Recommended
129 + $pubkey = isset($_REQUEST['pubkey']) ? WPRAccount::sanitizeKey(wp_unslash($_REQUEST['pubkey'])) : '';
105 130
106 - if (array_key_exists('rcvracc', $_REQUEST)) {
131 + if (array_key_exists('rcvracc', $_REQUEST)) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
107 132 $account = WPRRecover::find($bvsettings, $pubkey);
108 133 } else {
109 134 $account = WPRAccount::find($bvsettings, $pubkey);
110 135 }
111 136
112 - $request = new BVCallbackRequest($account, $_REQUEST);
137 + $request = new BVCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
113 138 $response = new BVCallbackResponse($request->bvb64cksize);
114 139
115 - if ($account && (1 === $account->authenticate($request))) {
116 - define('WPRBASEPATH', plugin_dir_path(__FILE__));
140 + if ($request->authenticate() === 1) {
141 + if (array_key_exists('bv_ignr_frm_cptch', $_REQUEST)) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
142 + #handling of Contact Forms 7
143 + add_filter('wpcf7_skip_spam_check', '__return_true', PHP_INT_MAX, 2);
117 144
145 + #handling of Formidable plugin
146 + add_filter('frm_is_field_hidden', '__return_true', PHP_INT_MAX, 3);
118 147
119 - require_once dirname( __FILE__ ) . '/callback/handler.php';
148 + #handling of WP Forms plugin
149 + add_filter('wpforms_process_bypass_captcha', '__return_true', PHP_INT_MAX, 3);
120 150
121 - $params = $request->processParams($_REQUEST);
122 - if ($params === false) {
123 - $resp = array(
124 - "account_info" => $account->info(),
125 - "request_info" => $request->info(),
126 - "bvinfo" => $bvinfo->info(),
127 - "statusmsg" => "BVPRMS_CORRUPTED"
128 - );
129 - $response->terminate($resp);
151 + #handling of Forminator plugin
152 + if (defined('WP_PLUGIN_DIR')) {
153 + $abstractFrontActionFilePath = WP_PLUGIN_DIR . '/forminator/library/abstracts/abstract-class-front-action.php';
154 + $frontActionFilePath = WP_PLUGIN_DIR . '/forminator/library/modules/custom-forms/front/front-action.php';
155 +
156 + if (file_exists($abstractFrontActionFilePath) && file_exists($frontActionFilePath)) {
157 + require_once $abstractFrontActionFilePath;
158 + require_once $frontActionFilePath;
159 + if (class_exists('Forminator_CForm_Front_Action')) {
160 + Forminator_CForm_Front_Action::$hidden_fields[] = "bv-stripe-";
161 + }
162 + }
163 + }
164 +
165 + #handling of CleanTalk Antispam plugin
166 + add_action('init', function() {
167 + global $apbct;
168 + if (isset($apbct) && is_object($apbct)) {
169 + $apbct->settings['forms__contact_forms_test'] = 0;
170 + }
171 + });
172 +
173 + #handling of Akismet plugin
174 + add_filter('akismet_get_api_key', function($api_key) { return null; }, PHP_INT_MAX);
175 +
176 + #handling of Formidable Antispam
177 + add_filter('frm_validate_entry', function($errors, $values, $args) {
178 + unset($errors['spam']); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
179 + return $errors;
180 + }, PHP_INT_MAX, 3);
181 +
182 + #handling of Gravity Form plugin
183 + if (isset($_REQUEST['form_id'])) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
184 + $form_id = sanitize_text_field(wp_unslash($_REQUEST['form_id'])); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
185 + add_filter('gform_pre_validation_' . $form_id, function($form) {
186 + foreach ($form['fields'] as &$field) {
187 + if ($field['type'] === 'captcha') {
188 + $field->visibility = 'hidden';
189 + }
190 + }
191 + return $form;
192 + }, PHP_INT_MAX, 1);
193 + }
194 +
195 + #handling of Ninja Form plugin
196 + add_filter('ninja_forms_pre_validate_field_settings', function($field_settings) {
197 + if (isset($field_settings['type']) && in_array($field_settings['type'], array('recaptcha', 'spam'), true)) {
198 + $field_settings['type'] = null;
199 + }
200 +
201 + return $field_settings;
202 + }, PHP_INT_MAX, 1);
203 +
204 + add_filter('ninja_forms_run_action_type_recaptcha', '__return_false', PHP_INT_MAX);
130 205 }
131 - $request->params = $params;
132 - $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
133 - if ($request->is_afterload) {
134 - add_action('wp_loaded', array($callback_handler, 'execute'));
135 - } else if ($request->is_admin_ajax) {
136 - add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
137 - add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
138 - } else {
139 - $callback_handler->execute();
206 +
207 + if (array_key_exists('bv_ignr_eml', $_REQUEST)) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
208 + #handling of Gravity Form's Email
209 + add_filter('gform_pre_send_email', function($email_data) {
210 + $email_data['abort_email'] = true;
211 + return $email_data;
212 + }, PHP_INT_MAX, 1);
213 +
214 + #handling of Ninja Form's Email
215 + add_filter('ninja_forms_action_email_send', '__return_true', PHP_INT_MAX);
216 +
217 + #handling of Contact Form 7's Email
218 + add_action('wpcf7_before_send_mail', function($contact_form, &$abort) { $abort = true; }, PHP_INT_MAX, 2);
219 +
220 + #handling of WP Form's Email
221 + add_filter('wpforms_entry_email', '__return_false', PHP_INT_MAX);
222 +
223 + #handling of Formidable Form's Email
224 + add_filter('frm_send_email', '__return_false', PHP_INT_MAX);
225 +
226 + #handling of Forminator Form's Email
227 + foreach (['poll', 'quiz', 'form'] as $type) {
228 + add_filter("forminator_{$type}_get_admin_email_recipients", function() {
229 + return [];
230 + }, PHP_INT_MAX);
231 + }
140 232 }
233 +
234 + if (!array_key_exists('bv_ignr_frm_cptch', $_REQUEST) && !array_key_exists('bv_ignr_eml', $_REQUEST)) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
235 + define('WPRBASEPATH', plugin_dir_path(__FILE__));
236 +
237 +
238 + require_once dirname( __FILE__ ) . '/callback/handler.php';
239 +
240 + $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
241 + if ($params === false) {
242 + $response->terminate($request->corruptedParamsResp());
243 + }
244 + $request->params = $params;
245 + $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
246 + if ($request->is_afterload) {
247 + add_action('wp_loaded', array($callback_handler, 'execute'));
248 + } else if ($request->is_admin_ajax) {
249 + add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
250 + add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
251 + } else {
252 + $callback_handler->execute();
253 + }
254 + }
141 255 } else {
142 - $resp = array(
143 - "account_info" => $account ? $account->info() : array("error" => "ACCOUNT_NOT_FOUND"),
144 - "request_info" => $request->info(),
145 - "bvinfo" => $bvinfo->info(),
146 - "statusmsg" => "FAILED_AUTH",
147 - "api_pubkey" => substr(WPRAccount::getApiPublicKey($bvsettings), 0, 8),
148 - "def_sigmatch" => substr(WPRAccount::getSigMatch($request, WPRRecover::getDefaultSecret($bvsettings)), 0, 8)
149 - );
150 - $response->terminate($resp);
256 + $response->terminate($request->authFailedResp());
151 257 }
152 258 } else {
153 259 if ($bvinfo->hasValidDBVersion()) {
154 260 if ($bvinfo->isProtectModuleEnabled()) {
155 - require_once dirname( __FILE__ ) . '/protect/wp/protect.php';
156 - $bvprotect = new BVProtect($bvdb, $bvsettings);
157 - $bvprotect->init();
158 - if ($bvinfo->isActivePlugin() && !(defined( 'WP_CLI' ) && WP_CLI)) {
159 - $bvprotect->run();
261 + require_once dirname( __FILE__ ) . '/protect/protect.php';
262 + //For backward compatibility.
263 + WPRProtect_V588::$settings = new WPRWPSettings();
264 + WPRProtect_V588::$db = new WPRWPDb();
265 + WPRProtect_V588::$info = new WPRInfo(WPRProtect_V588::$settings);
266 +
267 + add_action('wpr_clear_pt_config', array('WPRProtect_V588', 'uninstall'));
268 +
269 + if ($bvinfo->isActivePlugin()) {
270 + WPRProtect_V588::init(WPRProtect_V588::MODE_WP);
271 + }
160 272 }
161 - }
162 273
163 274 if ($bvinfo->isDynSyncModuleEnabled()) {
164 275 require_once dirname( __FILE__ ) . '/wp_dynsync.php';
165 276 $bvconfig = $bvinfo->config;
@@ -192,5 +303,18 @@
192 303 if (is_admin()) {
193 304 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
194 305 }
195 306
196 -}
307 + ##THIRDPARTYCACHINGMODULE##
308 +}
309 +
310 +if (WPRWP2FA::isEnabled($bvsettings)) {
311 + $wp_2fa = new WPRWP2FA();
312 + $wp_2fa->init();
313 +}
314 +
315 +if (!empty($bvinfo->getLPWhitelabelInfo())) {
316 + $wp_login_whitelabel = new WPRWPLoginWhitelabel();
317 + $wp_login_whitelabel->init();
318 +}
319 +
320 +add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));