PluginProbe
The WP Remote WordPress Plugin / 6.36
The WP Remote WordPress Plugin v6.36
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | wp_admin.php +84 -63 5.246.36 View file →
@@ -24,9 +24,9 @@
24 24 }
25 25 }
26 26
27 27 function removeAdminNotices() {
28 - if (array_key_exists('page', $_REQUEST) && $_REQUEST['page'] == $this->bvinfo->plugname) {
28 + if (WPRHelper::getRawParam('REQUEST', 'page') === $this->bvinfo->plugname) {
29 29 remove_all_actions('admin_notices');
30 30 remove_all_actions('all_admin_notices');
31 31 }
32 32 }
@@ -33,40 +33,44 @@
33 33
34 34 public function initHandler() {
35 35 if (!current_user_can('activate_plugins'))
36 36 return;
37 + $bvnonce = WPRHelper::getRawParam('REQUEST', 'bvnonce');
38 + $blogvaultkey = WPRHelper::getRawParam('REQUEST', 'blogvaultkey');
39 + $blogvaultkey = $blogvaultkey ? WPRAccount::sanitizeKey($blogvaultkey) : "";
37 40
38 - if (array_key_exists('bvnonce', $_REQUEST) &&
39 - wp_verify_nonce($_REQUEST['bvnonce'], "bvnonce") &&
40 - array_key_exists('blogvaultkey', $_REQUEST) &&
41 - (strlen(WPRAccount::sanitizeKey($_REQUEST['blogvaultkey'])) == 64) &&
42 - (array_key_exists('page', $_REQUEST) &&
43 - $_REQUEST['page'] == $this->bvinfo->plugname)) {
44 - $keys = str_split($_REQUEST['blogvaultkey'], 32);
41 + if ($bvnonce && wp_verify_nonce($bvnonce, "bvnonce") &&
42 + $blogvaultkey && strlen($blogvaultkey) == 64 &&
43 + (WPRHelper::getRawParam('REQUEST', 'page') === $this->bvinfo->plugname)) {
44 + $keys = str_split($blogvaultkey, 32);
45 45 WPRAccount::addAccount($this->settings, $keys[0], $keys[1]);
46 - if (array_key_exists('redirect', $_REQUEST)) {
47 - $location = $_REQUEST['redirect'];
46 +
47 + $location = WPRHelper::getStringParamSanitized('REQUEST', 'redirect', 'url');
48 + if ($location) {
48 49 wp_redirect($this->bvinfo->appUrl()."/dash/redir?q=".urlencode($location));
49 50 exit();
50 51 }
51 52 }
53 +
52 54 if ($this->bvinfo->isActivateRedirectSet()) {
53 55 $this->settings->updateOption($this->bvinfo->plug_redirect, 'no');
54 56 ##ACTIVATEREDIRECTCODE##
55 - wp_redirect($this->mainUrl());
57 + if (!wp_doing_ajax()) {
58 + wp_redirect($this->mainUrl());
59 + }
56 60 }
57 61 }
58 62
59 63 public function wprsecAdminMenu($hook) {
60 64 if ($hook === 'toplevel_page_wpremote' || WPRHelper::safePregMatch("/wpr_add_account$/", $hook) || WPRHelper::safePregMatch("/wpr_account_details$/", $hook)) {
61 - wp_enqueue_style( 'bootstrap', plugins_url('css/bootstrap.min.css', __FILE__));
62 - wp_enqueue_style( 'bvplugin', plugins_url('css/bvplugin.min.css', __FILE__));
65 + wp_enqueue_style( 'bootstrap', plugins_url('css/bootstrap.min.css', __FILE__), array(), $this->bvinfo->version);
66 + wp_enqueue_style( 'bvplugin', plugins_url('css/bvplugin.min.css', __FILE__), array(), $this->bvinfo->version);
63 67 }
64 68 }
65 69
66 70 public function menu() {
67 - $brand = $this->bvinfo->getBrandInfo();
68 - if (!is_array($brand) || (!array_key_exists('hide', $brand) && !array_key_exists('hide_from_menu', $brand))) {
71 + $brand = $this->bvinfo->getPluginWhitelabelInfo();
72 + if (!array_key_exists('hide', $brand) && !array_key_exists('hide_from_menu', $brand)) {
69 73 $bname = $this->bvinfo->getBrandName();
70 74 $icon = $this->bvinfo->getBrandIcon();
71 75 add_menu_page($bname, $bname, 'manage_options', $this->bvinfo->plugname,
72 76 array($this, 'adminPage'), plugins_url($icon, __FILE__ ));
@@ -73,13 +77,17 @@
73 77 }
74 78 }
75 79
76 80 public function hidePluginUpdate($plugins) {
77 - $brand = $this->bvinfo->getBrandInfo();
78 - $bvslug = $this->bvinfo->slug;
79 - if (isset($plugins->response[$bvslug]) && is_array($brand)) {
80 - if (array_key_exists('hide_from_menu', $brand) || array_key_exists('hide', $brand)) {
81 - unset($plugins->response[$bvslug]);
81 + if (!$this->bvinfo->canWhiteLabel()) {
82 + return $plugins;
83 + }
84 + $whitelabel_infos = $this->bvinfo->getPluginsWhitelabelInfos();
85 + foreach ($whitelabel_infos as $slug => $brand) {
86 + if ($this->bvinfo->canWhiteLabel($slug) && isset($plugins->response[$slug]) && is_array($brand)) {
87 + if (array_key_exists('hide_from_menu', $brand) || array_key_exists('hide', $brand)) {
88 + unset($plugins->response[$slug]);
89 + }
82 90 }
83 91 }
84 92 return $plugins;
85 93 }
@@ -84,14 +92,16 @@
84 92 return $plugins;
85 93 }
86 94
87 95 public function hidePluginDetails($plugin_metas, $slug) {
88 - $brand = $this->bvinfo->getBrandInfo();
89 - $bvslug = $this->bvinfo->slug;
90 -
91 - if ($slug === $bvslug && is_array($brand) && array_key_exists('hide_plugin_details', $brand)){
96 + if (!is_array($plugin_metas) || !$this->bvinfo->canWhiteLabel($slug)) {
97 + return $plugin_metas;
98 + }
99 + $whitelabel_info = $this->bvinfo->getPluginWhitelabelInfo($slug);
100 + if (array_key_exists('hide_plugin_details', $whitelabel_info)) {
92 101 foreach ($plugin_metas as $pluginKey => $pluginValue) {
93 - if (strpos($pluginValue, sprintf('>%s<', translate('View details')))) {
102 + // phpcs:ignore WordPress.WP.I18n.MissingArgDomain
103 + if (strpos($pluginValue, sprintf('>%s<', __('View details')))) {
94 104 unset($plugin_metas[$pluginKey]);
95 105 break;
96 106 }
97 107 }
@@ -99,31 +109,33 @@
99 109 return $plugin_metas;
100 110 }
101 111
102 112 public function handlePluginHealthInfo($plugins) {
103 - $brand = $this->bvinfo->getBrandInfo();
104 - $title = $this->bvinfo->title;
105 113 if (!isset($plugins["wp-plugins-active"]) ||
106 - !isset($plugins["wp-plugins-active"]["fields"]) ||
107 - !isset($plugins["wp-plugins-active"]["fields"][$title])) {
114 + !isset($plugins["wp-plugins-active"]["fields"]) || !$this->bvinfo->canWhiteLabel()) {
108 115 return $plugins;
109 116 }
110 - if (is_array($brand)) {
111 - if (array_key_exists('hide', $brand)) {
112 - unset($plugins["wp-plugins-active"]["fields"][$title]);
113 - } else {
114 - $plugin = $plugins["wp-plugins-active"]["fields"][$title];
115 - $author = $this->bvinfo->author;
116 - if (array_key_exists('name', $brand)) {
117 - $plugin["label"] = $brand['name'];
117 +
118 + $whitelabel_infos_by_title = $this->bvinfo->getPluginsWhitelabelInfoByTitle();
119 +
120 + foreach ($whitelabel_infos_by_title as $title => $brand) {
121 + if (is_array($brand) && array_key_exists('slug', $brand) && $this->bvinfo->canWhiteLabel($brand["slug"])) {
122 + if (array_key_exists('hide', $brand)) {
123 + unset($plugins["wp-plugins-active"]["fields"][$title]);
124 + } else {
125 + $plugin = $plugins["wp-plugins-active"]["fields"][$title];
126 + $author = $brand['default_author'];
127 + if (array_key_exists('name', $brand)) {
128 + $plugin["label"] = $brand['name'];
129 + }
130 + if (array_key_exists('author', $brand)) {
131 + $plugin["value"] = str_replace($author, $brand['author'], $plugin["value"]);
132 + }
133 + if (array_key_exists('description', $brand)) {
134 + $plugin["debug"] = str_replace($author, $brand['author'], $plugin["debug"]);
135 + }
136 + $plugins["wp-plugins-active"]["fields"][$title] = $plugin;
118 137 }
119 - if (array_key_exists('author', $brand)) {
120 - $plugin["value"] = str_replace($author, $brand['author'], $plugin["value"]);
121 - }
122 - if (array_key_exists('description', $brand)) {
123 - $plugin["debug"] = str_replace($author, $brand['author'], $plugin["debug"]);
124 - }
125 - $plugins["wp-plugins-active"]["fields"][$title] = $plugin;
126 138 }
127 139 }
128 140 return $plugins;
129 141 }
@@ -129,12 +141,13 @@
129 141 }
130 142
131 143 public function settingsLink($links, $file) {
132 144 #XNOTE: Fix this
133 - if ( $file == plugin_basename( dirname(__FILE__).'/blogvault.php' ) ) {
134 - $brand = $this->bvinfo->getBrandInfo();
135 - if (!$brand || !array_key_exists('hide_plugin_details', $brand)) {
136 - $links[] = '<a href="'.$this->mainUrl().'">'.__( 'Settings' ).'</a>';
145 + if ( $file == plugin_basename( dirname(__FILE__).'/plugin.php' ) ) {
146 + $brand = $this->bvinfo->getPluginWhitelabelInfo();
147 + if (!array_key_exists('hide_plugin_details', $brand)) {
148 + // phpcs:ignore WordPress.WP.I18n.MissingArgDomain
149 + $links[] = '<a href="'.$this->mainUrl().'">'.__('Settings').'</a>';
137 150 }
138 151 }
139 152 return $links;
140 153 }
@@ -139,10 +152,10 @@
139 152 return $links;
140 153 }
141 154
142 155 public function getPluginLogo() {
143 - $brand = $this->bvinfo->getBrandInfo();
144 - if (is_array($brand) && array_key_exists('logo', $brand)) {
156 + $brand = $this->bvinfo->getPluginWhitelabelInfo();
157 + if (array_key_exists('logo', $brand)) {
145 158 return $brand['logo'];
146 159 }
147 160 return $this->bvinfo->logo;
148 161 }
@@ -147,10 +160,10 @@
147 160 return $this->bvinfo->logo;
148 161 }
149 162
150 163 public function getWebPage() {
151 - $brand = $this->bvinfo->getBrandInfo();
152 - if (is_array($brand) && array_key_exists('webpage', $brand)) {
164 + $brand = $this->bvinfo->getPluginWhitelabelInfo();
165 + if (array_key_exists('webpage', $brand)) {
153 166 return $brand['webpage'];
154 167 }
155 168 return $this->bvinfo->webpage;
156 169 }
@@ -159,8 +172,9 @@
159 172 require_once dirname( __FILE__ ) . '/recover.php';
160 173 $bvnonce = wp_create_nonce("bvnonce");
161 174 $public = WPRAccount::getApiPublicKey($this->settings);
162 175 $secret = WPRRecover::defaultSecret($this->settings);
176 + $server_ip = WPRHelper::getStringParamEscaped('SERVER', 'SERVER_ADDR', 'attr');
163 177 $tags = "<input type='hidden' name='url' value='".esc_attr($this->siteinfo->wpurl())."'/>\n".
164 178 "<input type='hidden' name='homeurl' value='".esc_attr($this->siteinfo->homeurl())."'/>\n".
165 179 "<input type='hidden' name='siteurl' value='".esc_attr($this->siteinfo->siteurl())."'/>\n".
166 180 "<input type='hidden' name='dbsig' value='".esc_attr($this->siteinfo->dbsig(false))."'/>\n".
@@ -166,9 +180,9 @@
166 180 "<input type='hidden' name='dbsig' value='".esc_attr($this->siteinfo->dbsig(false))."'/>\n".
167 181 "<input type='hidden' name='plug' value='".esc_attr($this->bvinfo->plugname)."'/>\n".
168 182 "<input type='hidden' name='adminurl' value='".esc_attr($this->mainUrl())."'/>\n".
169 183 "<input type='hidden' name='bvversion' value='".esc_attr($this->bvinfo->version)."'/>\n".
170 - "<input type='hidden' name='serverip' value='".esc_attr($_SERVER["SERVER_ADDR"])."'/>\n".
184 + "<input type='hidden' name='serverip' value='".$server_ip."'/>\n".
171 185 "<input type='hidden' name='abspath' value='".esc_attr(ABSPATH)."'/>\n".
172 186 "<input type='hidden' name='secret' value='".esc_attr($secret)."'/>\n".
173 187 "<input type='hidden' name='public' value='".esc_attr($public)."'/>\n".
174 188 "<input type='hidden' name='bvnonce' value='".esc_attr($bvnonce)."'/>\n";
@@ -195,13 +209,20 @@
195 209 require_once dirname( __FILE__ ) . "/admin/account_details.php";
196 210 }
197 211
198 212 public function adminPage() {
199 - if (isset($_REQUEST['bvnonce']) && wp_verify_nonce( $_REQUEST['bvnonce'], 'bvnonce' )) {
213 + $bvnonce = WPRHelper::getRawParam('REQUEST', 'bvnonce');
214 + if ($bvnonce && wp_verify_nonce($bvnonce, 'bvnonce')) {
200 215 $info = array();
201 216 $this->siteinfo->basic($info);
202 - $this->bvapi->pingbv('/bvapi/disconnect', $info, $_REQUEST['pubkey']);
203 - WPRAccount::remove($this->settings, $_REQUEST['pubkey']);
217 +
218 + $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
219 +
220 + if (!empty($pubkey)) {
221 + $pubkey = WPRAccount::sanitizeKey($pubkey);
222 + $this->bvapi->pingbv('/bvapi/disconnect', $info, $pubkey);
223 + WPRAccount::remove($this->settings, $pubkey);
224 + }
204 225 }
205 226 if (WPRAccount::isConfigured($this->settings)) {
206 227 if (!isset($_REQUEST['add_account'])) {
207 228 $this->showAccountDetailsPage();
@@ -212,17 +233,17 @@
212 233 $this->showAddAccountPage();
213 234 }
214 235 }
215 236
216 - public function initBranding($plugins) {
217 - $slug = $this->bvinfo->slug;
218 -
219 - if (!is_array($plugins) || !isset($slug, $plugins)) {
237 + public function initWhitelabel($plugins) {
238 + if (!is_array($plugins) || !$this->bvinfo->canWhiteLabel()) {
220 239 return $plugins;
221 240 }
222 -
223 - $brand = $this->bvinfo->getBrandInfo();
224 - if (is_array($brand)) {
241 + $whitelabel_infos = $this->bvinfo->getPluginsWhitelabelInfos();
242 + foreach ($whitelabel_infos as $slug => $brand) {
243 + if (!isset($slug) || !$this->bvinfo->canWhiteLabel($slug) || !array_key_exists($slug, $plugins) || !is_array($brand)) {
244 + continue;
245 + }
225 246 if (array_key_exists('hide', $brand)) {
226 247 unset($plugins[$slug]);
227 248 } else {
228 249 if (array_key_exists('name', $brand)) {