PluginProbe
The WP Remote WordPress Plugin / 6.76
The WP Remote WordPress Plugin v6.76
6.76 6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 All 54 releases
← All changes | plugin.php +95 -36 5.416.76 View file →
@@ -4,10 +4,12 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 5.41
8 +Version: 6.76
9 9 Network: True
10 +License: GPLv2 or later
11 +License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
10 12 */
11 13
12 14 /* Copyright 2017 WP Remote (email : support@wpremote.com)
13 15
@@ -37,8 +39,13 @@
37 39 require_once dirname( __FILE__ ) . '/wp_actions.php';
38 40 require_once dirname( __FILE__ ) . '/info.php';
39 41 require_once dirname( __FILE__ ) . '/account.php';
40 42 require_once dirname( __FILE__ ) . '/helper.php';
43 +require_once dirname( __FILE__ ) . '/wp_file_system.php';
44 +require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
45 +
46 +require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
47 +
41 48 ##WPCACHEMODULE##
42 49
43 50
44 51 $bvsettings = new WPRWPSettings();
@@ -53,20 +60,23 @@
53 60 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
54 61 register_activation_hook(__FILE__, array($wp_action, 'activate'));
55 62 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
56 63
64 +
57 65 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
58 -add_action('clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
66 +add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
67 +
59 68 ##SOADDUNINSTALLACTION##
60 69
61 70 ##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
62 71
63 72 ##WPCLIMODULE##
73 +
64 74 if (is_admin()) {
65 75 require_once dirname( __FILE__ ) . '/wp_admin.php';
66 76 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
67 77 add_action('admin_init', array($wpadmin, 'initHandler'));
68 - add_filter('all_plugins', array($wpadmin, 'initBranding'));
78 + add_filter('all_plugins', array($wpadmin, 'initWhitelabel'));
69 79 add_filter('plugin_row_meta', array($wpadmin, 'hidePluginDetails'), 10, 2);
70 80 add_filter('debug_information', array($wpadmin, 'handlePluginHealthInfo'), 10, 1);
71 81 if ($bvsiteinfo->isMultisite()) {
72 82 add_action('network_admin_menu', array($wpadmin, 'menu'));
@@ -74,55 +84,63 @@
74 84 add_action('admin_menu', array($wpadmin, 'menu'));
75 85 }
76 86 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
77 87 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
88 +
89 + ##MG_AJAX_ACTIONS##
90 + ##POPUP_ON_DEACTIVATION##
78 91 add_action('admin_notices', array($wpadmin, 'activateWarning'));
79 92 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
80 - ##ALPURGECACHEFUNCTION##
81 - ##ALADMINMENU##
82 93 }
83 94
84 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
85 - $_REQUEST = array_merge($_GET, $_POST);
95 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
96 + $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
86 97 }
87 98
99 +#Service active check
100 +if ($bvinfo->config != false) {
101 + add_action('wpr_remove_bv_preload_include', array($wp_action, 'removeBVPreload'));
102 +}
103 +
104 +require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
105 +WPRWPPHPErrorMonitoring::init();
106 +
107 +require_once dirname( __FILE__ ) . '/wp_actlog.php';
108 +$actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvinfo->isActivityLogActive() ? $bvinfo->config['activity_log'] : array());
109 +$actlog->init();
110 +
88 111 if ($bvinfo->hasValidDBVersion()) {
89 - if ($bvinfo->isServiceActive('activity_log')) {
90 - require_once dirname( __FILE__ ) . '/wp_actlog.php';
91 - $bvconfig = $bvinfo->config;
92 - $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
93 - $actlog->init();
94 - }
95 -
112 + ##MAINTENANCEMODULE##
96 113 }
97 114
98 -if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
115 +if (WPRHelper::getRawParam('REQUEST', 'bvplugname') == "wpremote") {
99 116 require_once dirname( __FILE__ ) . '/callback/base.php';
100 117 require_once dirname( __FILE__ ) . '/callback/response.php';
101 118 require_once dirname( __FILE__ ) . '/callback/request.php';
102 119 require_once dirname( __FILE__ ) . '/recover.php';
103 120
104 - $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
121 + $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
122 + $pubkey = isset($pubkey) ? WPRAccount::sanitizeKey($pubkey) : '';
123 + $rcvracc = WPRHelper::getRawParam('REQUEST', 'rcvracc');
105 124
106 - if (array_key_exists('rcvracc', $_REQUEST)) {
107 - $account = WPRRecover::find($bvsettings, $pubkey);
125 + if (isset($rcvracc)) {
126 + $bvctag = WPRHelper::getRawParam('REQUEST', 'bvctag');
127 + $bvctag = isset($bvctag) ? WPRAccount::sanitizeKey($bvctag) : null;
128 + $account = WPRRecover::find($bvsettings, $pubkey, $bvctag);
108 129 } else {
109 130 $account = WPRAccount::find($bvsettings, $pubkey);
110 131 }
111 132
112 - $request = new BVCallbackRequest($account, $_REQUEST, $bvsettings);
113 - $response = new BVCallbackResponse($request->bvb64cksize);
133 + $request = new WPRCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
134 + $response = new WPRCallbackResponse($request->bvb64cksize);
114 135
115 136 if ($request->authenticate() === 1) {
116 - if (array_key_exists('bv_ignr_frm_cptch', $_REQUEST)) {
117 - #handling of Contact Forms 7
118 - add_filter('wpcf7_skip_spam_check', '__return_true', PHP_INT_MAX, 2);
137 + $bv_frm_tstng = WPRHelper::getRawParam('REQUEST', 'bv_frm_tstng');
138 + if (isset($bv_frm_tstng)) {
139 + require_once dirname(__FILE__) . '/form_testing/form_testing.php';
140 + $form_testing = new BVFormTesting($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
141 + $form_testing->init();
119 142
120 - #handling of Formidable plugin
121 - add_filter('frm_is_field_hidden', '__return_true', PHP_INT_MAX, 3);
122 -
123 - #handling of WP Forms plugin
124 - add_filter('wpforms_process_bypass_captcha', '__return_true', PHP_INT_MAX, 3);
125 143 } else {
126 144 define('WPRBASEPATH', plugin_dir_path(__FILE__));
127 145
128 146
@@ -127,15 +145,17 @@
127 145
128 146
129 147 require_once dirname( __FILE__ ) . '/callback/handler.php';
130 148
131 - $params = $request->processParams($_REQUEST);
149 + $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
132 150 if ($params === false) {
133 151 $response->terminate($request->corruptedParamsResp());
134 152 }
135 153 $request->params = $params;
136 - $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
137 - if ($request->is_afterload) {
154 + $callback_handler = new WPRCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
155 + if ($request->is_aftershutdown) {
156 + $callback_handler->deferExecutionUntilShutdown();
157 + } else if ($request->is_afterload) {
138 158 add_action('wp_loaded', array($callback_handler, 'execute'));
139 159 } else if ($request->is_admin_ajax) {
140 160 add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
141 161 add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
@@ -149,11 +169,17 @@
149 169 } else {
150 170 if ($bvinfo->hasValidDBVersion()) {
151 171 if ($bvinfo->isProtectModuleEnabled()) {
152 172 require_once dirname( __FILE__ ) . '/protect/protect.php';
153 - add_action('clear_pt_config', array('WPRProtect_V541', 'uninstall'));
154 - if ($bvinfo->isActivePlugin() && !(defined( 'WP_CLI' ) && WP_CLI)) {
155 - WPRProtect_V541::init(WPRProtect_V541::MODE_WP);
173 + //For backward compatibility.
174 + WPRProtect_V676::$settings = new WPRWPSettings();
175 + WPRProtect_V676::$db = new WPRWPDb();
176 + WPRProtect_V676::$info = new WPRInfo(WPRProtect_V676::$settings);
177 +
178 + add_action('wpr_clear_pt_config', array('WPRProtect_V676', 'uninstall'));
179 +
180 + if ($bvinfo->isActivePlugin()) {
181 + WPRProtect_V676::init(WPRProtect_V676::MODE_WP);
156 182 }
157 183 }
158 184
159 185 if ($bvinfo->isDynSyncModuleEnabled()) {
@@ -164,9 +190,9 @@
164 190 }
165 191
166 192 }
167 193 $bv_site_settings = $bvsettings->getOption('bv_site_settings');
168 - if (isset($bv_site_settings)) {
194 + if (is_array($bv_site_settings)) {
169 195 if (isset($bv_site_settings['wp_auto_updates'])) {
170 196 $wp_auto_updates = $bv_site_settings['wp_auto_updates'];
171 197 if (array_key_exists('block_auto_update_core', $wp_auto_updates)) {
172 198 add_filter('auto_update_core', '__return_false' );
@@ -182,8 +208,28 @@
182 208 if (array_key_exists('block_auto_update_translation', $wp_auto_updates)) {
183 209 add_filter('auto_update_translation', '__return_false' );
184 210 }
185 211 }
212 +
213 + if (isset($bv_site_settings['security_hardening'])) {
214 + $bv_security_hardening = $bv_site_settings['security_hardening'];
215 + if (is_array($bv_security_hardening) &&
216 + isset($bv_security_hardening['version']) &&
217 + $bv_security_hardening['version'] === 1) {
218 + if (isset($bv_security_hardening['disable_file_editor']) &&
219 + $bv_security_hardening['disable_file_editor'] === true &&
220 + !defined('DISALLOW_FILE_EDIT')) {
221 + define('DISALLOW_FILE_EDIT', true);
222 + }
223 +
224 + if (isset($bv_security_hardening['block_file_modifications']) &&
225 + $bv_security_hardening['block_file_modifications'] === true &&
226 + !defined('DISALLOW_FILE_MODS')) {
227 + define('DISALLOW_FILE_MODS', true);
228 + }
229 + }
230 + }
231 +
186 232 }
187 233
188 234 if (is_admin()) {
189 235 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
@@ -189,5 +235,18 @@
189 235 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
190 236 }
191 237
192 238 ##THIRDPARTYCACHINGMODULE##
193 -}
239 +}
240 +
241 +if (WPRWP2FA::isEnabled($bvsettings)) {
242 + $wp_2fa = new WPRWP2FA();
243 + $wp_2fa->init();
244 +}
245 +
246 +if (!empty($bvinfo->getLPWhitelabelInfo())) {
247 + $wp_login_whitelabel = new WPRWPLoginWhitelabel();
248 + $wp_login_whitelabel->init();
249 +}
250 +
251 +add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));
252 +##PLUGIN_LOADED_MODULE##