PluginProbe
The WP Remote WordPress Plugin / trunk
The WP Remote WordPress Plugin vtrunk
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | plugin.php +114 -52 4.87trunk View file →
@@ -4,10 +4,12 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 4.87
8 +Version: 6.72
9 9 Network: True
10 +License: GPLv2 or later
11 +License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
10 12 */
11 13
12 14 /* Copyright 2017 WP Remote (email : support@wpremote.com)
13 15
@@ -36,8 +38,14 @@
36 38 require_once dirname( __FILE__ ) . '/wp_api.php';
37 39 require_once dirname( __FILE__ ) . '/wp_actions.php';
38 40 require_once dirname( __FILE__ ) . '/info.php';
39 41 require_once dirname( __FILE__ ) . '/account.php';
42 +require_once dirname( __FILE__ ) . '/helper.php';
43 +require_once dirname( __FILE__ ) . '/wp_file_system.php';
44 +require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
45 +
46 +require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
47 +
40 48 ##WPCACHEMODULE##
41 49
42 50
43 51 $bvsettings = new WPRWPSettings();
@@ -52,18 +60,23 @@
52 60 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
53 61 register_activation_hook(__FILE__, array($wp_action, 'activate'));
54 62 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
55 63
64 +
56 65 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
57 -add_action('clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
66 +add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
67 +
58 68 ##SOADDUNINSTALLACTION##
59 69
70 +##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
71 +
60 72 ##WPCLIMODULE##
73 +
61 74 if (is_admin()) {
62 75 require_once dirname( __FILE__ ) . '/wp_admin.php';
63 76 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
64 77 add_action('admin_init', array($wpadmin, 'initHandler'));
65 - add_filter('all_plugins', array($wpadmin, 'initBranding'));
78 + add_filter('all_plugins', array($wpadmin, 'initWhitelabel'));
66 79 add_filter('plugin_row_meta', array($wpadmin, 'hidePluginDetails'), 10, 2);
67 80 add_filter('debug_information', array($wpadmin, 'handlePluginHealthInfo'), 10, 1);
68 81 if ($bvsiteinfo->isMultisite()) {
69 82 add_action('network_admin_menu', array($wpadmin, 'menu'));
@@ -71,18 +84,27 @@
71 84 add_action('admin_menu', array($wpadmin, 'menu'));
72 85 }
73 86 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
74 87 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
88 +
89 + ##MG_AJAX_ACTIONS##
90 + ##POPUP_ON_DEACTIVATION##
75 91 add_action('admin_notices', array($wpadmin, 'activateWarning'));
76 92 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
77 - ##ALPURGECACHEFUNCTION##
78 - ##ALADMINMENU##
79 93 }
80 94
81 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
82 - $_REQUEST = array_merge($_GET, $_POST);
95 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
96 + $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
83 97 }
84 98
99 +#Service active check
100 +if ($bvinfo->config != false) {
101 + add_action('wpr_remove_bv_preload_include', array($wp_action, 'removeBVPreload'));
102 +}
103 +
104 +require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
105 +WPRWPPHPErrorMonitoring::init();
106 +
85 107 if ($bvinfo->hasValidDBVersion()) {
86 108 if ($bvinfo->isServiceActive('activity_log')) {
87 109 require_once dirname( __FILE__ ) . '/wp_actlog.php';
88 110 $bvconfig = $bvinfo->config;
@@ -89,74 +111,80 @@
89 111 $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
90 112 $actlog->init();
91 113 }
92 114
115 + ##MAINTENANCEMODULE##
93 116 }
94 117
95 -if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
118 +if (WPRHelper::getRawParam('REQUEST', 'bvplugname') == "wpremote") {
96 119 require_once dirname( __FILE__ ) . '/callback/base.php';
97 120 require_once dirname( __FILE__ ) . '/callback/response.php';
98 121 require_once dirname( __FILE__ ) . '/callback/request.php';
99 122 require_once dirname( __FILE__ ) . '/recover.php';
100 123
101 - $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
124 + $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
125 + $pubkey = isset($pubkey) ? WPRAccount::sanitizeKey($pubkey) : '';
126 + $rcvracc = WPRHelper::getRawParam('REQUEST', 'rcvracc');
102 127
103 - if (array_key_exists('rcvracc', $_REQUEST)) {
104 - $account = WPRRecover::find($bvsettings, $pubkey);
128 + if (isset($rcvracc)) {
129 + $bvctag = WPRHelper::getRawParam('REQUEST', 'bvctag');
130 + $bvctag = isset($bvctag) ? WPRAccount::sanitizeKey($bvctag) : null;
131 + $account = WPRRecover::find($bvsettings, $pubkey, $bvctag);
105 132 } else {
106 133 $account = WPRAccount::find($bvsettings, $pubkey);
107 134 }
108 135
109 - $request = new BVCallbackRequest($account, $_REQUEST);
110 - $response = new BVCallbackResponse($request->bvb64cksize);
136 + $request = new WPRCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
137 + $response = new WPRCallbackResponse($request->bvb64cksize);
111 138
112 - if ($account && (1 === $account->authenticate($request))) {
113 - define('WPRBASEPATH', plugin_dir_path(__FILE__));
139 + if ($request->authenticate() === 1) {
140 + $bv_frm_tstng = WPRHelper::getRawParam('REQUEST', 'bv_frm_tstng');
141 + if (isset($bv_frm_tstng)) {
142 + require_once dirname(__FILE__) . '/form_testing/form_testing.php';
143 + $form_testing = new BVFormTesting($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
144 + $form_testing->init();
114 145
146 + } else {
147 + define('WPRBASEPATH', plugin_dir_path(__FILE__));
115 148
116 - require_once dirname( __FILE__ ) . '/callback/handler.php';
117 149
118 - $params = $request->processParams($_REQUEST);
119 - if ($params === false) {
120 - $resp = array(
121 - "account_info" => $account->info(),
122 - "request_info" => $request->info(),
123 - "bvinfo" => $bvinfo->info(),
124 - "statusmsg" => "BVPRMS_CORRUPTED"
125 - );
126 - $response->terminate($resp);
150 + require_once dirname( __FILE__ ) . '/callback/handler.php';
151 +
152 + $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
153 + if ($params === false) {
154 + $response->terminate($request->corruptedParamsResp());
155 + }
156 + $request->params = $params;
157 + $callback_handler = new WPRCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
158 + if ($request->is_aftershutdown) {
159 + $callback_handler->deferExecutionUntilShutdown();
160 + } else if ($request->is_afterload) {
161 + add_action('wp_loaded', array($callback_handler, 'execute'));
162 + } else if ($request->is_admin_ajax) {
163 + add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
164 + add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
165 + } else {
166 + $callback_handler->execute();
167 + }
127 168 }
128 - $request->params = $params;
129 - $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
130 - if ($request->is_afterload) {
131 - add_action('wp_loaded', array($callback_handler, 'execute'));
132 - } else if ($request->is_admin_ajax) {
133 - add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
134 - add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
135 - } else {
136 - $callback_handler->execute();
137 - }
138 169 } else {
139 - $resp = array(
140 - "account_info" => $account ? $account->info() : array("error" => "ACCOUNT_NOT_FOUND"),
141 - "request_info" => $request->info(),
142 - "bvinfo" => $bvinfo->info(),
143 - "statusmsg" => "FAILED_AUTH",
144 - "api_pubkey" => substr(WPRAccount::getApiPublicKey($bvsettings), 0, 8),
145 - "def_sigmatch" => substr(WPRAccount::getSigMatch($request, WPRRecover::getDefaultSecret($bvsettings)), 0, 8)
146 - );
147 - $response->terminate($resp);
170 + $response->terminate($request->authFailedResp());
148 171 }
149 172 } else {
150 173 if ($bvinfo->hasValidDBVersion()) {
151 174 if ($bvinfo->isProtectModuleEnabled()) {
152 - require_once dirname( __FILE__ ) . '/protect/wp/protect.php';
153 - $bvprotect = new BVProtect($bvdb, $bvsettings);
154 - $bvprotect->init();
155 - if ($bvinfo->isActivePlugin() && !(defined( 'WP_CLI' ) && WP_CLI)) {
156 - $bvprotect->run();
175 + require_once dirname( __FILE__ ) . '/protect/protect.php';
176 + //For backward compatibility.
177 + WPRProtect_V672::$settings = new WPRWPSettings();
178 + WPRProtect_V672::$db = new WPRWPDb();
179 + WPRProtect_V672::$info = new WPRInfo(WPRProtect_V672::$settings);
180 +
181 + add_action('wpr_clear_pt_config', array('WPRProtect_V672', 'uninstall'));
182 +
183 + if ($bvinfo->isActivePlugin()) {
184 + WPRProtect_V672::init(WPRProtect_V672::MODE_WP);
185 + }
157 186 }
158 - }
159 187
160 188 if ($bvinfo->isDynSyncModuleEnabled()) {
161 189 require_once dirname( __FILE__ ) . '/wp_dynsync.php';
162 190 $bvconfig = $bvinfo->config;
@@ -165,9 +193,9 @@
165 193 }
166 194
167 195 }
168 196 $bv_site_settings = $bvsettings->getOption('bv_site_settings');
169 - if (isset($bv_site_settings)) {
197 + if (is_array($bv_site_settings)) {
170 198 if (isset($bv_site_settings['wp_auto_updates'])) {
171 199 $wp_auto_updates = $bv_site_settings['wp_auto_updates'];
172 200 if (array_key_exists('block_auto_update_core', $wp_auto_updates)) {
173 201 add_filter('auto_update_core', '__return_false' );
@@ -183,8 +211,28 @@
183 211 if (array_key_exists('block_auto_update_translation', $wp_auto_updates)) {
184 212 add_filter('auto_update_translation', '__return_false' );
185 213 }
186 214 }
215 +
216 + if (isset($bv_site_settings['security_hardening'])) {
217 + $bv_security_hardening = $bv_site_settings['security_hardening'];
218 + if (is_array($bv_security_hardening) &&
219 + isset($bv_security_hardening['version']) &&
220 + $bv_security_hardening['version'] === 1) {
221 + if (isset($bv_security_hardening['disable_file_editor']) &&
222 + $bv_security_hardening['disable_file_editor'] === true &&
223 + !defined('DISALLOW_FILE_EDIT')) {
224 + define('DISALLOW_FILE_EDIT', true);
225 + }
226 +
227 + if (isset($bv_security_hardening['block_file_modifications']) &&
228 + $bv_security_hardening['block_file_modifications'] === true &&
229 + !defined('DISALLOW_FILE_MODS')) {
230 + define('DISALLOW_FILE_MODS', true);
231 + }
232 + }
233 + }
234 +
187 235 }
188 236
189 237 if (is_admin()) {
190 238 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
@@ -189,5 +237,19 @@
189 237 if (is_admin()) {
190 238 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
191 239 }
192 240
193 -}
241 + ##THIRDPARTYCACHINGMODULE##
242 +}
243 +
244 +if (WPRWP2FA::isEnabled($bvsettings)) {
245 + $wp_2fa = new WPRWP2FA();
246 + $wp_2fa->init();
247 +}
248 +
249 +if (!empty($bvinfo->getLPWhitelabelInfo())) {
250 + $wp_login_whitelabel = new WPRWPLoginWhitelabel();
251 + $wp_login_whitelabel->init();
252 +}
253 +
254 +add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));
255 +##PLUGIN_LOADED_MODULE##