PluginProbe
The WP Remote WordPress Plugin / 6.65
The WP Remote WordPress Plugin v6.65
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | plugin.php +112 -52 4.976.65 View file →
@@ -4,10 +4,12 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 4.97
8 +Version: 6.65
9 9 Network: True
10 +License: GPLv2 or later
11 +License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
10 12 */
11 13
12 14 /* Copyright 2017 WP Remote (email : support@wpremote.com)
13 15
@@ -36,8 +38,14 @@
36 38 require_once dirname( __FILE__ ) . '/wp_api.php';
37 39 require_once dirname( __FILE__ ) . '/wp_actions.php';
38 40 require_once dirname( __FILE__ ) . '/info.php';
39 41 require_once dirname( __FILE__ ) . '/account.php';
42 +require_once dirname( __FILE__ ) . '/helper.php';
43 +require_once dirname( __FILE__ ) . '/wp_file_system.php';
44 +require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
45 +
46 +require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
47 +
40 48 ##WPCACHEMODULE##
41 49
42 50
43 51 $bvsettings = new WPRWPSettings();
@@ -52,20 +60,23 @@
52 60 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
53 61 register_activation_hook(__FILE__, array($wp_action, 'activate'));
54 62 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
55 63
64 +
56 65 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
57 -add_action('clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
66 +add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
67 +
58 68 ##SOADDUNINSTALLACTION##
59 69
60 70 ##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
61 71
62 72 ##WPCLIMODULE##
73 +
63 74 if (is_admin()) {
64 75 require_once dirname( __FILE__ ) . '/wp_admin.php';
65 76 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
66 77 add_action('admin_init', array($wpadmin, 'initHandler'));
67 - add_filter('all_plugins', array($wpadmin, 'initBranding'));
78 + add_filter('all_plugins', array($wpadmin, 'initWhitelabel'));
68 79 add_filter('plugin_row_meta', array($wpadmin, 'hidePluginDetails'), 10, 2);
69 80 add_filter('debug_information', array($wpadmin, 'handlePluginHealthInfo'), 10, 1);
70 81 if ($bvsiteinfo->isMultisite()) {
71 82 add_action('network_admin_menu', array($wpadmin, 'menu'));
@@ -73,18 +84,27 @@
73 84 add_action('admin_menu', array($wpadmin, 'menu'));
74 85 }
75 86 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
76 87 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
88 +
89 + ##MG_AJAX_ACTIONS##
90 + ##POPUP_ON_DEACTIVATION##
77 91 add_action('admin_notices', array($wpadmin, 'activateWarning'));
78 92 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
79 - ##ALPURGECACHEFUNCTION##
80 - ##ALADMINMENU##
81 93 }
82 94
83 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
84 - $_REQUEST = array_merge($_GET, $_POST);
95 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
96 + $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
85 97 }
86 98
99 +#Service active check
100 +if ($bvinfo->config != false) {
101 + add_action('wpr_remove_bv_preload_include', array($wp_action, 'removeBVPreload'));
102 +}
103 +
104 +require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
105 +WPRWPPHPErrorMonitoring::init();
106 +
87 107 if ($bvinfo->hasValidDBVersion()) {
88 108 if ($bvinfo->isServiceActive('activity_log')) {
89 109 require_once dirname( __FILE__ ) . '/wp_actlog.php';
90 110 $bvconfig = $bvinfo->config;
@@ -91,74 +111,80 @@
91 111 $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
92 112 $actlog->init();
93 113 }
94 114
115 + ##MAINTENANCEMODULE##
95 116 }
96 117
97 -if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
118 +if (WPRHelper::getRawParam('REQUEST', 'bvplugname') == "wpremote") {
98 119 require_once dirname( __FILE__ ) . '/callback/base.php';
99 120 require_once dirname( __FILE__ ) . '/callback/response.php';
100 121 require_once dirname( __FILE__ ) . '/callback/request.php';
101 122 require_once dirname( __FILE__ ) . '/recover.php';
102 123
103 - $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
124 + $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
125 + $pubkey = isset($pubkey) ? WPRAccount::sanitizeKey($pubkey) : '';
126 + $rcvracc = WPRHelper::getRawParam('REQUEST', 'rcvracc');
104 127
105 - if (array_key_exists('rcvracc', $_REQUEST)) {
106 - $account = WPRRecover::find($bvsettings, $pubkey);
128 + if (isset($rcvracc)) {
129 + $bvctag = WPRHelper::getRawParam('REQUEST', 'bvctag');
130 + $bvctag = isset($bvctag) ? WPRAccount::sanitizeKey($bvctag) : null;
131 + $account = WPRRecover::find($bvsettings, $pubkey, $bvctag);
107 132 } else {
108 133 $account = WPRAccount::find($bvsettings, $pubkey);
109 134 }
110 135
111 - $request = new BVCallbackRequest($account, $_REQUEST);
112 - $response = new BVCallbackResponse($request->bvb64cksize);
136 + $request = new WPRCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
137 + $response = new WPRCallbackResponse($request->bvb64cksize);
113 138
114 - if ($account && (1 === $account->authenticate($request))) {
115 - define('WPRBASEPATH', plugin_dir_path(__FILE__));
139 + if ($request->authenticate() === 1) {
140 + $bv_frm_tstng = WPRHelper::getRawParam('REQUEST', 'bv_frm_tstng');
141 + if (isset($bv_frm_tstng)) {
142 + require_once dirname(__FILE__) . '/form_testing/form_testing.php';
143 + $form_testing = new BVFormTesting($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
144 + $form_testing->init();
116 145
146 + } else {
147 + define('WPRBASEPATH', plugin_dir_path(__FILE__));
117 148
118 - require_once dirname( __FILE__ ) . '/callback/handler.php';
119 149
120 - $params = $request->processParams($_REQUEST);
121 - if ($params === false) {
122 - $resp = array(
123 - "account_info" => $account->info(),
124 - "request_info" => $request->info(),
125 - "bvinfo" => $bvinfo->info(),
126 - "statusmsg" => "BVPRMS_CORRUPTED"
127 - );
128 - $response->terminate($resp);
150 + require_once dirname( __FILE__ ) . '/callback/handler.php';
151 +
152 + $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
153 + if ($params === false) {
154 + $response->terminate($request->corruptedParamsResp());
155 + }
156 + $request->params = $params;
157 + $callback_handler = new WPRCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
158 + if ($request->is_aftershutdown) {
159 + $callback_handler->deferExecutionUntilShutdown();
160 + } else if ($request->is_afterload) {
161 + add_action('wp_loaded', array($callback_handler, 'execute'));
162 + } else if ($request->is_admin_ajax) {
163 + add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
164 + add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
165 + } else {
166 + $callback_handler->execute();
167 + }
129 168 }
130 - $request->params = $params;
131 - $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
132 - if ($request->is_afterload) {
133 - add_action('wp_loaded', array($callback_handler, 'execute'));
134 - } else if ($request->is_admin_ajax) {
135 - add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
136 - add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
137 - } else {
138 - $callback_handler->execute();
139 - }
140 169 } else {
141 - $resp = array(
142 - "account_info" => $account ? $account->info() : array("error" => "ACCOUNT_NOT_FOUND"),
143 - "request_info" => $request->info(),
144 - "bvinfo" => $bvinfo->info(),
145 - "statusmsg" => "FAILED_AUTH",
146 - "api_pubkey" => substr(WPRAccount::getApiPublicKey($bvsettings), 0, 8),
147 - "def_sigmatch" => substr(WPRAccount::getSigMatch($request, WPRRecover::getDefaultSecret($bvsettings)), 0, 8)
148 - );
149 - $response->terminate($resp);
170 + $response->terminate($request->authFailedResp());
150 171 }
151 172 } else {
152 173 if ($bvinfo->hasValidDBVersion()) {
153 174 if ($bvinfo->isProtectModuleEnabled()) {
154 - require_once dirname( __FILE__ ) . '/protect/wp/protect.php';
155 - $bvprotect = new BVProtect($bvdb, $bvsettings);
156 - $bvprotect->init();
157 - if ($bvinfo->isActivePlugin() && !(defined( 'WP_CLI' ) && WP_CLI)) {
158 - $bvprotect->run();
175 + require_once dirname( __FILE__ ) . '/protect/protect.php';
176 + //For backward compatibility.
177 + WPRProtect_V665::$settings = new WPRWPSettings();
178 + WPRProtect_V665::$db = new WPRWPDb();
179 + WPRProtect_V665::$info = new WPRInfo(WPRProtect_V665::$settings);
180 +
181 + add_action('wpr_clear_pt_config', array('WPRProtect_V665', 'uninstall'));
182 +
183 + if ($bvinfo->isActivePlugin()) {
184 + WPRProtect_V665::init(WPRProtect_V665::MODE_WP);
185 + }
159 186 }
160 - }
161 187
162 188 if ($bvinfo->isDynSyncModuleEnabled()) {
163 189 require_once dirname( __FILE__ ) . '/wp_dynsync.php';
164 190 $bvconfig = $bvinfo->config;
@@ -167,9 +193,9 @@
167 193 }
168 194
169 195 }
170 196 $bv_site_settings = $bvsettings->getOption('bv_site_settings');
171 - if (isset($bv_site_settings)) {
197 + if (is_array($bv_site_settings)) {
172 198 if (isset($bv_site_settings['wp_auto_updates'])) {
173 199 $wp_auto_updates = $bv_site_settings['wp_auto_updates'];
174 200 if (array_key_exists('block_auto_update_core', $wp_auto_updates)) {
175 201 add_filter('auto_update_core', '__return_false' );
@@ -185,8 +211,28 @@
185 211 if (array_key_exists('block_auto_update_translation', $wp_auto_updates)) {
186 212 add_filter('auto_update_translation', '__return_false' );
187 213 }
188 214 }
215 +
216 + if (isset($bv_site_settings['security_hardening'])) {
217 + $bv_security_hardening = $bv_site_settings['security_hardening'];
218 + if (is_array($bv_security_hardening) &&
219 + isset($bv_security_hardening['version']) &&
220 + $bv_security_hardening['version'] === 1) {
221 + if (isset($bv_security_hardening['disable_file_editor']) &&
222 + $bv_security_hardening['disable_file_editor'] === true &&
223 + !defined('DISALLOW_FILE_EDIT')) {
224 + define('DISALLOW_FILE_EDIT', true);
225 + }
226 +
227 + if (isset($bv_security_hardening['block_file_modifications']) &&
228 + $bv_security_hardening['block_file_modifications'] === true &&
229 + !defined('DISALLOW_FILE_MODS')) {
230 + define('DISALLOW_FILE_MODS', true);
231 + }
232 + }
233 + }
234 +
189 235 }
190 236
191 237 if (is_admin()) {
192 238 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
@@ -191,5 +237,19 @@
191 237 if (is_admin()) {
192 238 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
193 239 }
194 240
195 -}
241 + ##THIRDPARTYCACHINGMODULE##
242 +}
243 +
244 +if (WPRWP2FA::isEnabled($bvsettings)) {
245 + $wp_2fa = new WPRWP2FA();
246 + $wp_2fa->init();
247 +}
248 +
249 +if (!empty($bvinfo->getLPWhitelabelInfo())) {
250 + $wp_login_whitelabel = new WPRWPLoginWhitelabel();
251 + $wp_login_whitelabel->init();
252 +}
253 +
254 +add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));
255 +##PLUGIN_LOADED_MODULE##