PluginProbe
The WP Remote WordPress Plugin / 6.36
The WP Remote WordPress Plugin v6.36
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | wp_admin.php +34 -20 5.426.36 View file →
@@ -24,9 +24,9 @@
24 24 }
25 25 }
26 26
27 27 function removeAdminNotices() {
28 - if (array_key_exists('page', $_REQUEST) && $_REQUEST['page'] == $this->bvinfo->plugname) {
28 + if (WPRHelper::getRawParam('REQUEST', 'page') === $this->bvinfo->plugname) {
29 29 remove_all_actions('admin_notices');
30 30 remove_all_actions('all_admin_notices');
31 31 }
32 32 }
@@ -33,34 +33,38 @@
33 33
34 34 public function initHandler() {
35 35 if (!current_user_can('activate_plugins'))
36 36 return;
37 + $bvnonce = WPRHelper::getRawParam('REQUEST', 'bvnonce');
38 + $blogvaultkey = WPRHelper::getRawParam('REQUEST', 'blogvaultkey');
39 + $blogvaultkey = $blogvaultkey ? WPRAccount::sanitizeKey($blogvaultkey) : "";
37 40
38 - if (array_key_exists('bvnonce', $_REQUEST) &&
39 - wp_verify_nonce($_REQUEST['bvnonce'], "bvnonce") &&
40 - array_key_exists('blogvaultkey', $_REQUEST) &&
41 - (strlen(WPRAccount::sanitizeKey($_REQUEST['blogvaultkey'])) == 64) &&
42 - (array_key_exists('page', $_REQUEST) &&
43 - $_REQUEST['page'] == $this->bvinfo->plugname)) {
44 - $keys = str_split($_REQUEST['blogvaultkey'], 32);
41 + if ($bvnonce && wp_verify_nonce($bvnonce, "bvnonce") &&
42 + $blogvaultkey && strlen($blogvaultkey) == 64 &&
43 + (WPRHelper::getRawParam('REQUEST', 'page') === $this->bvinfo->plugname)) {
44 + $keys = str_split($blogvaultkey, 32);
45 45 WPRAccount::addAccount($this->settings, $keys[0], $keys[1]);
46 - if (array_key_exists('redirect', $_REQUEST)) {
47 - $location = $_REQUEST['redirect'];
46 +
47 + $location = WPRHelper::getStringParamSanitized('REQUEST', 'redirect', 'url');
48 + if ($location) {
48 49 wp_redirect($this->bvinfo->appUrl()."/dash/redir?q=".urlencode($location));
49 50 exit();
50 51 }
51 52 }
53 +
52 54 if ($this->bvinfo->isActivateRedirectSet()) {
53 55 $this->settings->updateOption($this->bvinfo->plug_redirect, 'no');
54 56 ##ACTIVATEREDIRECTCODE##
55 - wp_redirect($this->mainUrl());
57 + if (!wp_doing_ajax()) {
58 + wp_redirect($this->mainUrl());
59 + }
56 60 }
57 61 }
58 62
59 63 public function wprsecAdminMenu($hook) {
60 64 if ($hook === 'toplevel_page_wpremote' || WPRHelper::safePregMatch("/wpr_add_account$/", $hook) || WPRHelper::safePregMatch("/wpr_account_details$/", $hook)) {
61 - wp_enqueue_style( 'bootstrap', plugins_url('css/bootstrap.min.css', __FILE__));
62 - wp_enqueue_style( 'bvplugin', plugins_url('css/bvplugin.min.css', __FILE__));
65 + wp_enqueue_style( 'bootstrap', plugins_url('css/bootstrap.min.css', __FILE__), array(), $this->bvinfo->version);
66 + wp_enqueue_style( 'bvplugin', plugins_url('css/bvplugin.min.css', __FILE__), array(), $this->bvinfo->version);
63 67 }
64 68 }
65 69
66 70 public function menu() {
@@ -94,9 +98,10 @@
94 98 }
95 99 $whitelabel_info = $this->bvinfo->getPluginWhitelabelInfo($slug);
96 100 if (array_key_exists('hide_plugin_details', $whitelabel_info)) {
97 101 foreach ($plugin_metas as $pluginKey => $pluginValue) {
98 - if (strpos($pluginValue, sprintf('>%s<', translate('View details')))) {
102 + // phpcs:ignore WordPress.WP.I18n.MissingArgDomain
103 + if (strpos($pluginValue, sprintf('>%s<', __('View details')))) {
99 104 unset($plugin_metas[$pluginKey]);
100 105 break;
101 106 }
102 107 }
@@ -136,12 +141,13 @@
136 141 }
137 142
138 143 public function settingsLink($links, $file) {
139 144 #XNOTE: Fix this
140 - if ( $file == plugin_basename( dirname(__FILE__).'/blogvault.php' ) ) {
145 + if ( $file == plugin_basename( dirname(__FILE__).'/plugin.php' ) ) {
141 146 $brand = $this->bvinfo->getPluginWhitelabelInfo();
142 147 if (!array_key_exists('hide_plugin_details', $brand)) {
143 - $links[] = '<a href="'.$this->mainUrl().'">'.__( 'Settings' ).'</a>';
148 + // phpcs:ignore WordPress.WP.I18n.MissingArgDomain
149 + $links[] = '<a href="'.$this->mainUrl().'">'.__('Settings').'</a>';
144 150 }
145 151 }
146 152 return $links;
147 153 }
@@ -166,8 +172,9 @@
166 172 require_once dirname( __FILE__ ) . '/recover.php';
167 173 $bvnonce = wp_create_nonce("bvnonce");
168 174 $public = WPRAccount::getApiPublicKey($this->settings);
169 175 $secret = WPRRecover::defaultSecret($this->settings);
176 + $server_ip = WPRHelper::getStringParamEscaped('SERVER', 'SERVER_ADDR', 'attr');
170 177 $tags = "<input type='hidden' name='url' value='".esc_attr($this->siteinfo->wpurl())."'/>\n".
171 178 "<input type='hidden' name='homeurl' value='".esc_attr($this->siteinfo->homeurl())."'/>\n".
172 179 "<input type='hidden' name='siteurl' value='".esc_attr($this->siteinfo->siteurl())."'/>\n".
173 180 "<input type='hidden' name='dbsig' value='".esc_attr($this->siteinfo->dbsig(false))."'/>\n".
@@ -173,9 +180,9 @@
173 180 "<input type='hidden' name='dbsig' value='".esc_attr($this->siteinfo->dbsig(false))."'/>\n".
174 181 "<input type='hidden' name='plug' value='".esc_attr($this->bvinfo->plugname)."'/>\n".
175 182 "<input type='hidden' name='adminurl' value='".esc_attr($this->mainUrl())."'/>\n".
176 183 "<input type='hidden' name='bvversion' value='".esc_attr($this->bvinfo->version)."'/>\n".
177 - "<input type='hidden' name='serverip' value='".esc_attr($_SERVER["SERVER_ADDR"])."'/>\n".
184 + "<input type='hidden' name='serverip' value='".$server_ip."'/>\n".
178 185 "<input type='hidden' name='abspath' value='".esc_attr(ABSPATH)."'/>\n".
179 186 "<input type='hidden' name='secret' value='".esc_attr($secret)."'/>\n".
180 187 "<input type='hidden' name='public' value='".esc_attr($public)."'/>\n".
181 188 "<input type='hidden' name='bvnonce' value='".esc_attr($bvnonce)."'/>\n";
@@ -202,13 +209,20 @@
202 209 require_once dirname( __FILE__ ) . "/admin/account_details.php";
203 210 }
204 211
205 212 public function adminPage() {
206 - if (isset($_REQUEST['bvnonce']) && wp_verify_nonce( $_REQUEST['bvnonce'], 'bvnonce' )) {
213 + $bvnonce = WPRHelper::getRawParam('REQUEST', 'bvnonce');
214 + if ($bvnonce && wp_verify_nonce($bvnonce, 'bvnonce')) {
207 215 $info = array();
208 216 $this->siteinfo->basic($info);
209 - $this->bvapi->pingbv('/bvapi/disconnect', $info, $_REQUEST['pubkey']);
210 - WPRAccount::remove($this->settings, $_REQUEST['pubkey']);
217 +
218 + $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
219 +
220 + if (!empty($pubkey)) {
221 + $pubkey = WPRAccount::sanitizeKey($pubkey);
222 + $this->bvapi->pingbv('/bvapi/disconnect', $info, $pubkey);
223 + WPRAccount::remove($this->settings, $pubkey);
224 + }
211 225 }
212 226 if (WPRAccount::isConfigured($this->settings)) {
213 227 if (!isset($_REQUEST['add_account'])) {
214 228 $this->showAccountDetailsPage();