PluginProbe
The WP Remote WordPress Plugin / 6.76
The WP Remote WordPress Plugin v6.76
6.76 6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 All 54 releases
← All changes | plugin.php +79 -65 5.726.76 View file →
@@ -4,10 +4,12 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 5.72
8 +Version: 6.76
9 9 Network: True
10 +License: GPLv2 or later
11 +License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
10 12 */
11 13
12 14 /* Copyright 2017 WP Remote (email : support@wpremote.com)
13 15
@@ -37,10 +39,13 @@
37 39 require_once dirname( __FILE__ ) . '/wp_actions.php';
38 40 require_once dirname( __FILE__ ) . '/info.php';
39 41 require_once dirname( __FILE__ ) . '/account.php';
40 42 require_once dirname( __FILE__ ) . '/helper.php';
43 +require_once dirname( __FILE__ ) . '/wp_file_system.php';
41 44 require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
42 45
46 +require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
47 +
43 48 ##WPCACHEMODULE##
44 49
45 50
46 51 $bvsettings = new WPRWPSettings();
@@ -55,15 +60,18 @@
55 60 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
56 61 register_activation_hook(__FILE__, array($wp_action, 'activate'));
57 62 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
58 63
64 +
59 65 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
60 66 add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
67 +
61 68 ##SOADDUNINSTALLACTION##
62 69
63 70 ##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
64 71
65 72 ##WPCLIMODULE##
73 +
66 74 if (is_admin()) {
67 75 require_once dirname( __FILE__ ) . '/wp_admin.php';
68 76 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
69 77 add_action('admin_init', array($wpadmin, 'initHandler'));
@@ -76,16 +84,17 @@
76 84 add_action('admin_menu', array($wpadmin, 'menu'));
77 85 }
78 86 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
79 87 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
88 +
89 + ##MG_AJAX_ACTIONS##
90 + ##POPUP_ON_DEACTIVATION##
80 91 add_action('admin_notices', array($wpadmin, 'activateWarning'));
81 92 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
82 - ##ALPURGECACHEFUNCTION##
83 - ##ALADMINMENU##
84 93 }
85 94
86 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
87 - $_REQUEST = array_merge($_GET, $_POST);
95 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
96 + $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
88 97 }
89 98
90 99 #Service active check
91 100 if ($bvinfo->config != false) {
@@ -94,74 +103,44 @@
94 103
95 104 require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
96 105 WPRWPPHPErrorMonitoring::init();
97 106
107 +require_once dirname( __FILE__ ) . '/wp_actlog.php';
108 +$actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvinfo->isActivityLogActive() ? $bvinfo->config['activity_log'] : array());
109 +$actlog->init();
110 +
98 111 if ($bvinfo->hasValidDBVersion()) {
99 - if ($bvinfo->isServiceActive('activity_log')) {
100 - require_once dirname( __FILE__ ) . '/wp_actlog.php';
101 - $bvconfig = $bvinfo->config;
102 - $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
103 - $actlog->init();
104 - }
105 -
106 - if ($bvinfo->isServiceActive('maintenance_mode')) {
107 - require_once dirname( __FILE__ ). '/maintenance/wp_maintenance.php';
108 - $bvconfig = $bvinfo->config;
109 - $maintenance = new BVWPMaintenance($bvconfig['maintenance_mode']);
110 - $maintenance->init();
111 - }
112 -
112 + ##MAINTENANCEMODULE##
113 113 }
114 114
115 -if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
115 +if (WPRHelper::getRawParam('REQUEST', 'bvplugname') == "wpremote") {
116 116 require_once dirname( __FILE__ ) . '/callback/base.php';
117 117 require_once dirname( __FILE__ ) . '/callback/response.php';
118 118 require_once dirname( __FILE__ ) . '/callback/request.php';
119 119 require_once dirname( __FILE__ ) . '/recover.php';
120 120
121 - $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
121 + $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
122 + $pubkey = isset($pubkey) ? WPRAccount::sanitizeKey($pubkey) : '';
123 + $rcvracc = WPRHelper::getRawParam('REQUEST', 'rcvracc');
122 124
123 - if (array_key_exists('rcvracc', $_REQUEST)) {
124 - $account = WPRRecover::find($bvsettings, $pubkey);
125 + if (isset($rcvracc)) {
126 + $bvctag = WPRHelper::getRawParam('REQUEST', 'bvctag');
127 + $bvctag = isset($bvctag) ? WPRAccount::sanitizeKey($bvctag) : null;
128 + $account = WPRRecover::find($bvsettings, $pubkey, $bvctag);
125 129 } else {
126 130 $account = WPRAccount::find($bvsettings, $pubkey);
127 131 }
128 132
129 - $request = new BVCallbackRequest($account, $_REQUEST, $bvsettings);
130 - $response = new BVCallbackResponse($request->bvb64cksize);
133 + $request = new WPRCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
134 + $response = new WPRCallbackResponse($request->bvb64cksize);
131 135
132 136 if ($request->authenticate() === 1) {
133 - if (array_key_exists('bv_ignr_frm_cptch', $_REQUEST)) {
134 - #handling of Contact Forms 7
135 - add_filter('wpcf7_skip_spam_check', '__return_true', PHP_INT_MAX, 2);
137 + $bv_frm_tstng = WPRHelper::getRawParam('REQUEST', 'bv_frm_tstng');
138 + if (isset($bv_frm_tstng)) {
139 + require_once dirname(__FILE__) . '/form_testing/form_testing.php';
140 + $form_testing = new BVFormTesting($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
141 + $form_testing->init();
136 142
137 - #handling of Formidable plugin
138 - add_filter('frm_is_field_hidden', '__return_true', PHP_INT_MAX, 3);
139 -
140 - #handling of WP Forms plugin
141 - add_filter('wpforms_process_bypass_captcha', '__return_true', PHP_INT_MAX, 3);
142 -
143 - #handling of Forminator plugin
144 - if (defined('WP_PLUGIN_DIR')) {
145 - $abstractFrontActionFilePath = WP_PLUGIN_DIR . '/forminator/library/abstracts/abstract-class-front-action.php';
146 - $frontActionFilePath = WP_PLUGIN_DIR . '/forminator/library/modules/custom-forms/front/front-action.php';
147 -
148 - if (file_exists($abstractFrontActionFilePath) && file_exists($frontActionFilePath)) {
149 - require_once $abstractFrontActionFilePath;
150 - require_once $frontActionFilePath;
151 - if (class_exists('Forminator_CForm_Front_Action')) {
152 - Forminator_CForm_Front_Action::$hidden_fields[] = "bv-stripe-";
153 - }
154 - }
155 - }
156 -
157 - #handling of CleanTalk Antispam plugin
158 - add_action('init', function() {
159 - global $apbct;
160 - if (isset($apbct) && is_object($apbct)) {
161 - $apbct->settings['forms__contact_forms_test'] = 0;
162 - }
163 - });
164 143 } else {
165 144 define('WPRBASEPATH', plugin_dir_path(__FILE__));
166 145
167 146
@@ -166,15 +145,17 @@
166 145
167 146
168 147 require_once dirname( __FILE__ ) . '/callback/handler.php';
169 148
170 - $params = $request->processParams($_REQUEST);
149 + $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
171 150 if ($params === false) {
172 151 $response->terminate($request->corruptedParamsResp());
173 152 }
174 153 $request->params = $params;
175 - $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
176 - if ($request->is_afterload) {
154 + $callback_handler = new WPRCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
155 + if ($request->is_aftershutdown) {
156 + $callback_handler->deferExecutionUntilShutdown();
157 + } else if ($request->is_afterload) {
177 158 add_action('wp_loaded', array($callback_handler, 'execute'));
178 159 } else if ($request->is_admin_ajax) {
179 160 add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
180 161 add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
@@ -189,16 +170,16 @@
189 170 if ($bvinfo->hasValidDBVersion()) {
190 171 if ($bvinfo->isProtectModuleEnabled()) {
191 172 require_once dirname( __FILE__ ) . '/protect/protect.php';
192 173 //For backward compatibility.
193 - WPRProtect_V572::$settings = new WPRWPSettings();
194 - WPRProtect_V572::$db = new WPRWPDb();
195 - WPRProtect_V572::$info = new WPRInfo(WPRProtect_V572::$settings);
174 + WPRProtect_V676::$settings = new WPRWPSettings();
175 + WPRProtect_V676::$db = new WPRWPDb();
176 + WPRProtect_V676::$info = new WPRInfo(WPRProtect_V676::$settings);
196 177
197 - add_action('wpr_clear_pt_config', array('WPRProtect_V572', 'uninstall'));
178 + add_action('wpr_clear_pt_config', array('WPRProtect_V676', 'uninstall'));
198 179
199 180 if ($bvinfo->isActivePlugin()) {
200 - WPRProtect_V572::init(WPRProtect_V572::MODE_WP);
181 + WPRProtect_V676::init(WPRProtect_V676::MODE_WP);
201 182 }
202 183 }
203 184
204 185 if ($bvinfo->isDynSyncModuleEnabled()) {
@@ -209,9 +190,9 @@
209 190 }
210 191
211 192 }
212 193 $bv_site_settings = $bvsettings->getOption('bv_site_settings');
213 - if (isset($bv_site_settings)) {
194 + if (is_array($bv_site_settings)) {
214 195 if (isset($bv_site_settings['wp_auto_updates'])) {
215 196 $wp_auto_updates = $bv_site_settings['wp_auto_updates'];
216 197 if (array_key_exists('block_auto_update_core', $wp_auto_updates)) {
217 198 add_filter('auto_update_core', '__return_false' );
@@ -227,8 +208,28 @@
227 208 if (array_key_exists('block_auto_update_translation', $wp_auto_updates)) {
228 209 add_filter('auto_update_translation', '__return_false' );
229 210 }
230 211 }
212 +
213 + if (isset($bv_site_settings['security_hardening'])) {
214 + $bv_security_hardening = $bv_site_settings['security_hardening'];
215 + if (is_array($bv_security_hardening) &&
216 + isset($bv_security_hardening['version']) &&
217 + $bv_security_hardening['version'] === 1) {
218 + if (isset($bv_security_hardening['disable_file_editor']) &&
219 + $bv_security_hardening['disable_file_editor'] === true &&
220 + !defined('DISALLOW_FILE_EDIT')) {
221 + define('DISALLOW_FILE_EDIT', true);
222 + }
223 +
224 + if (isset($bv_security_hardening['block_file_modifications']) &&
225 + $bv_security_hardening['block_file_modifications'] === true &&
226 + !defined('DISALLOW_FILE_MODS')) {
227 + define('DISALLOW_FILE_MODS', true);
228 + }
229 + }
230 + }
231 +
231 232 }
232 233
233 234 if (is_admin()) {
234 235 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
@@ -234,5 +235,18 @@
234 235 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
235 236 }
236 237
237 238 ##THIRDPARTYCACHINGMODULE##
238 -}
239 +}
240 +
241 +if (WPRWP2FA::isEnabled($bvsettings)) {
242 + $wp_2fa = new WPRWP2FA();
243 + $wp_2fa->init();
244 +}
245 +
246 +if (!empty($bvinfo->getLPWhitelabelInfo())) {
247 + $wp_login_whitelabel = new WPRWPLoginWhitelabel();
248 + $wp_login_whitelabel->init();
249 +}
250 +
251 +add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));
252 +##PLUGIN_LOADED_MODULE##