PluginProbe
The WP Remote WordPress Plugin / 6.76
The WP Remote WordPress Plugin v6.76
6.76 6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 All 54 releases
← All changes | plugin.php +113 -43 5.226.76 View file →
@@ -4,10 +4,12 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 5.22
8 +Version: 6.76
9 9 Network: True
10 +License: GPLv2 or later
11 +License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
10 12 */
11 13
12 14 /* Copyright 2017 WP Remote (email : support@wpremote.com)
13 15
@@ -37,8 +39,13 @@
37 39 require_once dirname( __FILE__ ) . '/wp_actions.php';
38 40 require_once dirname( __FILE__ ) . '/info.php';
39 41 require_once dirname( __FILE__ ) . '/account.php';
40 42 require_once dirname( __FILE__ ) . '/helper.php';
43 +require_once dirname( __FILE__ ) . '/wp_file_system.php';
44 +require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
45 +
46 +require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
47 +
41 48 ##WPCACHEMODULE##
42 49
43 50
44 51 $bvsettings = new WPRWPSettings();
@@ -53,20 +60,23 @@
53 60 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
54 61 register_activation_hook(__FILE__, array($wp_action, 'activate'));
55 62 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
56 63
64 +
57 65 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
58 -add_action('clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
66 +add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
67 +
59 68 ##SOADDUNINSTALLACTION##
60 69
61 70 ##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
62 71
63 72 ##WPCLIMODULE##
73 +
64 74 if (is_admin()) {
65 75 require_once dirname( __FILE__ ) . '/wp_admin.php';
66 76 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
67 77 add_action('admin_init', array($wpadmin, 'initHandler'));
68 - add_filter('all_plugins', array($wpadmin, 'initBranding'));
78 + add_filter('all_plugins', array($wpadmin, 'initWhitelabel'));
69 79 add_filter('plugin_row_meta', array($wpadmin, 'hidePluginDetails'), 10, 2);
70 80 add_filter('debug_information', array($wpadmin, 'handlePluginHealthInfo'), 10, 1);
71 81 if ($bvsiteinfo->isMultisite()) {
72 82 add_action('network_admin_menu', array($wpadmin, 'menu'));
@@ -74,65 +84,86 @@
74 84 add_action('admin_menu', array($wpadmin, 'menu'));
75 85 }
76 86 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
77 87 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
88 +
89 + ##MG_AJAX_ACTIONS##
90 + ##POPUP_ON_DEACTIVATION##
78 91 add_action('admin_notices', array($wpadmin, 'activateWarning'));
79 92 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
80 - ##ALPURGECACHEFUNCTION##
81 - ##ALADMINMENU##
82 93 }
83 94
84 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
85 - $_REQUEST = array_merge($_GET, $_POST);
95 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
96 + $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
86 97 }
87 98
99 +#Service active check
100 +if ($bvinfo->config != false) {
101 + add_action('wpr_remove_bv_preload_include', array($wp_action, 'removeBVPreload'));
102 +}
103 +
104 +require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
105 +WPRWPPHPErrorMonitoring::init();
106 +
107 +require_once dirname( __FILE__ ) . '/wp_actlog.php';
108 +$actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvinfo->isActivityLogActive() ? $bvinfo->config['activity_log'] : array());
109 +$actlog->init();
110 +
88 111 if ($bvinfo->hasValidDBVersion()) {
89 - if ($bvinfo->isServiceActive('activity_log')) {
90 - require_once dirname( __FILE__ ) . '/wp_actlog.php';
91 - $bvconfig = $bvinfo->config;
92 - $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
93 - $actlog->init();
94 - }
95 -
112 + ##MAINTENANCEMODULE##
96 113 }
97 114
98 -if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
115 +if (WPRHelper::getRawParam('REQUEST', 'bvplugname') == "wpremote") {
99 116 require_once dirname( __FILE__ ) . '/callback/base.php';
100 117 require_once dirname( __FILE__ ) . '/callback/response.php';
101 118 require_once dirname( __FILE__ ) . '/callback/request.php';
102 119 require_once dirname( __FILE__ ) . '/recover.php';
103 120
104 - $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
121 + $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
122 + $pubkey = isset($pubkey) ? WPRAccount::sanitizeKey($pubkey) : '';
123 + $rcvracc = WPRHelper::getRawParam('REQUEST', 'rcvracc');
105 124
106 - if (array_key_exists('rcvracc', $_REQUEST)) {
107 - $account = WPRRecover::find($bvsettings, $pubkey);
125 + if (isset($rcvracc)) {
126 + $bvctag = WPRHelper::getRawParam('REQUEST', 'bvctag');
127 + $bvctag = isset($bvctag) ? WPRAccount::sanitizeKey($bvctag) : null;
128 + $account = WPRRecover::find($bvsettings, $pubkey, $bvctag);
108 129 } else {
109 130 $account = WPRAccount::find($bvsettings, $pubkey);
110 131 }
111 132
112 - $request = new BVCallbackRequest($account, $_REQUEST, $bvsettings);
113 - $response = new BVCallbackResponse($request->bvb64cksize);
133 + $request = new WPRCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
134 + $response = new WPRCallbackResponse($request->bvb64cksize);
114 135
115 136 if ($request->authenticate() === 1) {
116 - define('WPRBASEPATH', plugin_dir_path(__FILE__));
137 + $bv_frm_tstng = WPRHelper::getRawParam('REQUEST', 'bv_frm_tstng');
138 + if (isset($bv_frm_tstng)) {
139 + require_once dirname(__FILE__) . '/form_testing/form_testing.php';
140 + $form_testing = new BVFormTesting($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
141 + $form_testing->init();
117 142
143 + } else {
144 + define('WPRBASEPATH', plugin_dir_path(__FILE__));
118 145
119 - require_once dirname( __FILE__ ) . '/callback/handler.php';
120 146
121 - $params = $request->processParams($_REQUEST);
122 - if ($params === false) {
123 - $response->terminate($request->corruptedParamsResp());
147 + require_once dirname( __FILE__ ) . '/callback/handler.php';
148 +
149 + $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
150 + if ($params === false) {
151 + $response->terminate($request->corruptedParamsResp());
152 + }
153 + $request->params = $params;
154 + $callback_handler = new WPRCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
155 + if ($request->is_aftershutdown) {
156 + $callback_handler->deferExecutionUntilShutdown();
157 + } else if ($request->is_afterload) {
158 + add_action('wp_loaded', array($callback_handler, 'execute'));
159 + } else if ($request->is_admin_ajax) {
160 + add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
161 + add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
162 + } else {
163 + $callback_handler->execute();
164 + }
124 165 }
125 - $request->params = $params;
126 - $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
127 - if ($request->is_afterload) {
128 - add_action('wp_loaded', array($callback_handler, 'execute'));
129 - } else if ($request->is_admin_ajax) {
130 - add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
131 - add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
132 - } else {
133 - $callback_handler->execute();
134 - }
135 166 } else {
136 167 $response->terminate($request->authFailedResp());
137 168 }
138 169 } else {
@@ -137,15 +168,20 @@
137 168 }
138 169 } else {
139 170 if ($bvinfo->hasValidDBVersion()) {
140 171 if ($bvinfo->isProtectModuleEnabled()) {
141 - require_once dirname( __FILE__ ) . '/protect/wp/protect.php';
142 - $bvprotect = new BVProtect($bvdb, $bvsettings);
143 - $bvprotect->init();
144 - if ($bvinfo->isActivePlugin() && !(defined( 'WP_CLI' ) && WP_CLI)) {
145 - $bvprotect->run();
172 + require_once dirname( __FILE__ ) . '/protect/protect.php';
173 + //For backward compatibility.
174 + WPRProtect_V676::$settings = new WPRWPSettings();
175 + WPRProtect_V676::$db = new WPRWPDb();
176 + WPRProtect_V676::$info = new WPRInfo(WPRProtect_V676::$settings);
177 +
178 + add_action('wpr_clear_pt_config', array('WPRProtect_V676', 'uninstall'));
179 +
180 + if ($bvinfo->isActivePlugin()) {
181 + WPRProtect_V676::init(WPRProtect_V676::MODE_WP);
182 + }
146 183 }
147 - }
148 184
149 185 if ($bvinfo->isDynSyncModuleEnabled()) {
150 186 require_once dirname( __FILE__ ) . '/wp_dynsync.php';
151 187 $bvconfig = $bvinfo->config;
@@ -154,9 +190,9 @@
154 190 }
155 191
156 192 }
157 193 $bv_site_settings = $bvsettings->getOption('bv_site_settings');
158 - if (isset($bv_site_settings)) {
194 + if (is_array($bv_site_settings)) {
159 195 if (isset($bv_site_settings['wp_auto_updates'])) {
160 196 $wp_auto_updates = $bv_site_settings['wp_auto_updates'];
161 197 if (array_key_exists('block_auto_update_core', $wp_auto_updates)) {
162 198 add_filter('auto_update_core', '__return_false' );
@@ -172,8 +208,28 @@
172 208 if (array_key_exists('block_auto_update_translation', $wp_auto_updates)) {
173 209 add_filter('auto_update_translation', '__return_false' );
174 210 }
175 211 }
212 +
213 + if (isset($bv_site_settings['security_hardening'])) {
214 + $bv_security_hardening = $bv_site_settings['security_hardening'];
215 + if (is_array($bv_security_hardening) &&
216 + isset($bv_security_hardening['version']) &&
217 + $bv_security_hardening['version'] === 1) {
218 + if (isset($bv_security_hardening['disable_file_editor']) &&
219 + $bv_security_hardening['disable_file_editor'] === true &&
220 + !defined('DISALLOW_FILE_EDIT')) {
221 + define('DISALLOW_FILE_EDIT', true);
222 + }
223 +
224 + if (isset($bv_security_hardening['block_file_modifications']) &&
225 + $bv_security_hardening['block_file_modifications'] === true &&
226 + !defined('DISALLOW_FILE_MODS')) {
227 + define('DISALLOW_FILE_MODS', true);
228 + }
229 + }
230 + }
231 +
176 232 }
177 233
178 234 if (is_admin()) {
179 235 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
@@ -178,5 +234,19 @@
178 234 if (is_admin()) {
179 235 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
180 236 }
181 237
182 -}
238 + ##THIRDPARTYCACHINGMODULE##
239 +}
240 +
241 +if (WPRWP2FA::isEnabled($bvsettings)) {
242 + $wp_2fa = new WPRWP2FA();
243 + $wp_2fa->init();
244 +}
245 +
246 +if (!empty($bvinfo->getLPWhitelabelInfo())) {
247 + $wp_login_whitelabel = new WPRWPLoginWhitelabel();
248 + $wp_login_whitelabel->init();
249 +}
250 +
251 +add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));
252 +##PLUGIN_LOADED_MODULE##