PluginProbe
The WP Remote WordPress Plugin / 6.76
The WP Remote WordPress Plugin v6.76
6.76 6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 All 54 releases
← All changes | plugin.php +115 -59 5.056.76 View file →
@@ -4,10 +4,12 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 5.05
8 +Version: 6.76
9 9 Network: True
10 +License: GPLv2 or later
11 +License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
10 12 */
11 13
12 14 /* Copyright 2017 WP Remote (email : support@wpremote.com)
13 15
@@ -37,8 +39,13 @@
37 39 require_once dirname( __FILE__ ) . '/wp_actions.php';
38 40 require_once dirname( __FILE__ ) . '/info.php';
39 41 require_once dirname( __FILE__ ) . '/account.php';
40 42 require_once dirname( __FILE__ ) . '/helper.php';
43 +require_once dirname( __FILE__ ) . '/wp_file_system.php';
44 +require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
45 +
46 +require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
47 +
41 48 ##WPCACHEMODULE##
42 49
43 50
44 51 $bvsettings = new WPRWPSettings();
@@ -53,20 +60,23 @@
53 60 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
54 61 register_activation_hook(__FILE__, array($wp_action, 'activate'));
55 62 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
56 63
64 +
57 65 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
58 -add_action('clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
66 +add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
67 +
59 68 ##SOADDUNINSTALLACTION##
60 69
61 70 ##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
62 71
63 72 ##WPCLIMODULE##
73 +
64 74 if (is_admin()) {
65 75 require_once dirname( __FILE__ ) . '/wp_admin.php';
66 76 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
67 77 add_action('admin_init', array($wpadmin, 'initHandler'));
68 - add_filter('all_plugins', array($wpadmin, 'initBranding'));
78 + add_filter('all_plugins', array($wpadmin, 'initWhitelabel'));
69 79 add_filter('plugin_row_meta', array($wpadmin, 'hidePluginDetails'), 10, 2);
70 80 add_filter('debug_information', array($wpadmin, 'handlePluginHealthInfo'), 10, 1);
71 81 if ($bvsiteinfo->isMultisite()) {
72 82 add_action('network_admin_menu', array($wpadmin, 'menu'));
@@ -74,92 +84,104 @@
74 84 add_action('admin_menu', array($wpadmin, 'menu'));
75 85 }
76 86 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
77 87 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
88 +
89 + ##MG_AJAX_ACTIONS##
90 + ##POPUP_ON_DEACTIVATION##
78 91 add_action('admin_notices', array($wpadmin, 'activateWarning'));
79 92 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
80 - ##ALPURGECACHEFUNCTION##
81 - ##ALADMINMENU##
82 93 }
83 94
84 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
85 - $_REQUEST = array_merge($_GET, $_POST);
95 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
96 + $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
86 97 }
87 98
99 +#Service active check
100 +if ($bvinfo->config != false) {
101 + add_action('wpr_remove_bv_preload_include', array($wp_action, 'removeBVPreload'));
102 +}
103 +
104 +require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
105 +WPRWPPHPErrorMonitoring::init();
106 +
107 +require_once dirname( __FILE__ ) . '/wp_actlog.php';
108 +$actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvinfo->isActivityLogActive() ? $bvinfo->config['activity_log'] : array());
109 +$actlog->init();
110 +
88 111 if ($bvinfo->hasValidDBVersion()) {
89 - if ($bvinfo->isServiceActive('activity_log')) {
90 - require_once dirname( __FILE__ ) . '/wp_actlog.php';
91 - $bvconfig = $bvinfo->config;
92 - $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
93 - $actlog->init();
94 - }
95 -
112 + ##MAINTENANCEMODULE##
96 113 }
97 114
98 -if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
115 +if (WPRHelper::getRawParam('REQUEST', 'bvplugname') == "wpremote") {
99 116 require_once dirname( __FILE__ ) . '/callback/base.php';
100 117 require_once dirname( __FILE__ ) . '/callback/response.php';
101 118 require_once dirname( __FILE__ ) . '/callback/request.php';
102 119 require_once dirname( __FILE__ ) . '/recover.php';
103 120
104 - $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
121 + $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
122 + $pubkey = isset($pubkey) ? WPRAccount::sanitizeKey($pubkey) : '';
123 + $rcvracc = WPRHelper::getRawParam('REQUEST', 'rcvracc');
105 124
106 - if (array_key_exists('rcvracc', $_REQUEST)) {
107 - $account = WPRRecover::find($bvsettings, $pubkey);
125 + if (isset($rcvracc)) {
126 + $bvctag = WPRHelper::getRawParam('REQUEST', 'bvctag');
127 + $bvctag = isset($bvctag) ? WPRAccount::sanitizeKey($bvctag) : null;
128 + $account = WPRRecover::find($bvsettings, $pubkey, $bvctag);
108 129 } else {
109 130 $account = WPRAccount::find($bvsettings, $pubkey);
110 131 }
111 132
112 - $request = new BVCallbackRequest($account, $_REQUEST);
113 - $response = new BVCallbackResponse($request->bvb64cksize);
133 + $request = new WPRCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
134 + $response = new WPRCallbackResponse($request->bvb64cksize);
114 135
115 - if ($account && (1 === $account->authenticate($request))) {
116 - define('WPRBASEPATH', plugin_dir_path(__FILE__));
136 + if ($request->authenticate() === 1) {
137 + $bv_frm_tstng = WPRHelper::getRawParam('REQUEST', 'bv_frm_tstng');
138 + if (isset($bv_frm_tstng)) {
139 + require_once dirname(__FILE__) . '/form_testing/form_testing.php';
140 + $form_testing = new BVFormTesting($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
141 + $form_testing->init();
117 142
143 + } else {
144 + define('WPRBASEPATH', plugin_dir_path(__FILE__));
118 145
119 - require_once dirname( __FILE__ ) . '/callback/handler.php';
120 146
121 - $params = $request->processParams($_REQUEST);
122 - if ($params === false) {
123 - $resp = array(
124 - "account_info" => $account->info(),
125 - "request_info" => $request->info(),
126 - "bvinfo" => $bvinfo->info(),
127 - "statusmsg" => "BVPRMS_CORRUPTED"
128 - );
129 - $response->terminate($resp);
147 + require_once dirname( __FILE__ ) . '/callback/handler.php';
148 +
149 + $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
150 + if ($params === false) {
151 + $response->terminate($request->corruptedParamsResp());
152 + }
153 + $request->params = $params;
154 + $callback_handler = new WPRCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
155 + if ($request->is_aftershutdown) {
156 + $callback_handler->deferExecutionUntilShutdown();
157 + } else if ($request->is_afterload) {
158 + add_action('wp_loaded', array($callback_handler, 'execute'));
159 + } else if ($request->is_admin_ajax) {
160 + add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
161 + add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
162 + } else {
163 + $callback_handler->execute();
164 + }
130 165 }
131 - $request->params = $params;
132 - $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
133 - if ($request->is_afterload) {
134 - add_action('wp_loaded', array($callback_handler, 'execute'));
135 - } else if ($request->is_admin_ajax) {
136 - add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
137 - add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
138 - } else {
139 - $callback_handler->execute();
140 - }
141 166 } else {
142 - $resp = array(
143 - "account_info" => $account ? $account->info() : array("error" => "ACCOUNT_NOT_FOUND"),
144 - "request_info" => $request->info(),
145 - "bvinfo" => $bvinfo->info(),
146 - "statusmsg" => "FAILED_AUTH",
147 - "api_pubkey" => substr(WPRAccount::getApiPublicKey($bvsettings), 0, 8),
148 - "def_sigmatch" => substr(WPRAccount::getSigMatch($request, WPRRecover::getDefaultSecret($bvsettings)), 0, 8)
149 - );
150 - $response->terminate($resp);
167 + $response->terminate($request->authFailedResp());
151 168 }
152 169 } else {
153 170 if ($bvinfo->hasValidDBVersion()) {
154 171 if ($bvinfo->isProtectModuleEnabled()) {
155 - require_once dirname( __FILE__ ) . '/protect/wp/protect.php';
156 - $bvprotect = new BVProtect($bvdb, $bvsettings);
157 - $bvprotect->init();
158 - if ($bvinfo->isActivePlugin() && !(defined( 'WP_CLI' ) && WP_CLI)) {
159 - $bvprotect->run();
172 + require_once dirname( __FILE__ ) . '/protect/protect.php';
173 + //For backward compatibility.
174 + WPRProtect_V676::$settings = new WPRWPSettings();
175 + WPRProtect_V676::$db = new WPRWPDb();
176 + WPRProtect_V676::$info = new WPRInfo(WPRProtect_V676::$settings);
177 +
178 + add_action('wpr_clear_pt_config', array('WPRProtect_V676', 'uninstall'));
179 +
180 + if ($bvinfo->isActivePlugin()) {
181 + WPRProtect_V676::init(WPRProtect_V676::MODE_WP);
182 + }
160 183 }
161 - }
162 184
163 185 if ($bvinfo->isDynSyncModuleEnabled()) {
164 186 require_once dirname( __FILE__ ) . '/wp_dynsync.php';
165 187 $bvconfig = $bvinfo->config;
@@ -168,9 +190,9 @@
168 190 }
169 191
170 192 }
171 193 $bv_site_settings = $bvsettings->getOption('bv_site_settings');
172 - if (isset($bv_site_settings)) {
194 + if (is_array($bv_site_settings)) {
173 195 if (isset($bv_site_settings['wp_auto_updates'])) {
174 196 $wp_auto_updates = $bv_site_settings['wp_auto_updates'];
175 197 if (array_key_exists('block_auto_update_core', $wp_auto_updates)) {
176 198 add_filter('auto_update_core', '__return_false' );
@@ -186,8 +208,28 @@
186 208 if (array_key_exists('block_auto_update_translation', $wp_auto_updates)) {
187 209 add_filter('auto_update_translation', '__return_false' );
188 210 }
189 211 }
212 +
213 + if (isset($bv_site_settings['security_hardening'])) {
214 + $bv_security_hardening = $bv_site_settings['security_hardening'];
215 + if (is_array($bv_security_hardening) &&
216 + isset($bv_security_hardening['version']) &&
217 + $bv_security_hardening['version'] === 1) {
218 + if (isset($bv_security_hardening['disable_file_editor']) &&
219 + $bv_security_hardening['disable_file_editor'] === true &&
220 + !defined('DISALLOW_FILE_EDIT')) {
221 + define('DISALLOW_FILE_EDIT', true);
222 + }
223 +
224 + if (isset($bv_security_hardening['block_file_modifications']) &&
225 + $bv_security_hardening['block_file_modifications'] === true &&
226 + !defined('DISALLOW_FILE_MODS')) {
227 + define('DISALLOW_FILE_MODS', true);
228 + }
229 + }
230 + }
231 +
190 232 }
191 233
192 234 if (is_admin()) {
193 235 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
@@ -192,5 +234,19 @@
192 234 if (is_admin()) {
193 235 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
194 236 }
195 237
196 -}
238 + ##THIRDPARTYCACHINGMODULE##
239 +}
240 +
241 +if (WPRWP2FA::isEnabled($bvsettings)) {
242 + $wp_2fa = new WPRWP2FA();
243 + $wp_2fa->init();
244 +}
245 +
246 +if (!empty($bvinfo->getLPWhitelabelInfo())) {
247 + $wp_login_whitelabel = new WPRWPLoginWhitelabel();
248 + $wp_login_whitelabel->init();
249 +}
250 +
251 +add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));
252 +##PLUGIN_LOADED_MODULE##