PluginProbe
The WP Remote WordPress Plugin / trunk
The WP Remote WordPress Plugin vtrunk
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | plugin.php +105 -32 5.38trunk View file →
@@ -4,10 +4,12 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 5.38
8 +Version: 6.72
9 9 Network: True
10 +License: GPLv2 or later
11 +License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
10 12 */
11 13
12 14 /* Copyright 2017 WP Remote (email : support@wpremote.com)
13 15
@@ -37,8 +39,13 @@
37 39 require_once dirname( __FILE__ ) . '/wp_actions.php';
38 40 require_once dirname( __FILE__ ) . '/info.php';
39 41 require_once dirname( __FILE__ ) . '/account.php';
40 42 require_once dirname( __FILE__ ) . '/helper.php';
43 +require_once dirname( __FILE__ ) . '/wp_file_system.php';
44 +require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
45 +
46 +require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
47 +
41 48 ##WPCACHEMODULE##
42 49
43 50
44 51 $bvsettings = new WPRWPSettings();
@@ -53,20 +60,23 @@
53 60 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
54 61 register_activation_hook(__FILE__, array($wp_action, 'activate'));
55 62 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
56 63
64 +
57 65 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
58 -add_action('clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
66 +add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
67 +
59 68 ##SOADDUNINSTALLACTION##
60 69
61 70 ##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
62 71
63 72 ##WPCLIMODULE##
73 +
64 74 if (is_admin()) {
65 75 require_once dirname( __FILE__ ) . '/wp_admin.php';
66 76 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
67 77 add_action('admin_init', array($wpadmin, 'initHandler'));
68 - add_filter('all_plugins', array($wpadmin, 'initBranding'));
78 + add_filter('all_plugins', array($wpadmin, 'initWhitelabel'));
69 79 add_filter('plugin_row_meta', array($wpadmin, 'hidePluginDetails'), 10, 2);
70 80 add_filter('debug_information', array($wpadmin, 'handlePluginHealthInfo'), 10, 1);
71 81 if ($bvsiteinfo->isMultisite()) {
72 82 add_action('network_admin_menu', array($wpadmin, 'menu'));
@@ -74,18 +84,27 @@
74 84 add_action('admin_menu', array($wpadmin, 'menu'));
75 85 }
76 86 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
77 87 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
88 +
89 + ##MG_AJAX_ACTIONS##
90 + ##POPUP_ON_DEACTIVATION##
78 91 add_action('admin_notices', array($wpadmin, 'activateWarning'));
79 92 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
80 - ##ALPURGECACHEFUNCTION##
81 - ##ALADMINMENU##
82 93 }
83 94
84 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
85 - $_REQUEST = array_merge($_GET, $_POST);
95 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
96 + $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
86 97 }
87 98
99 +#Service active check
100 +if ($bvinfo->config != false) {
101 + add_action('wpr_remove_bv_preload_include', array($wp_action, 'removeBVPreload'));
102 +}
103 +
104 +require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
105 +WPRWPPHPErrorMonitoring::init();
106 +
88 107 if ($bvinfo->hasValidDBVersion()) {
89 108 if ($bvinfo->isServiceActive('activity_log')) {
90 109 require_once dirname( __FILE__ ) . '/wp_actlog.php';
91 110 $bvconfig = $bvinfo->config;
@@ -92,47 +111,62 @@
92 111 $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
93 112 $actlog->init();
94 113 }
95 114
115 + ##MAINTENANCEMODULE##
96 116 }
97 117
98 -if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
118 +if (WPRHelper::getRawParam('REQUEST', 'bvplugname') == "wpremote") {
99 119 require_once dirname( __FILE__ ) . '/callback/base.php';
100 120 require_once dirname( __FILE__ ) . '/callback/response.php';
101 121 require_once dirname( __FILE__ ) . '/callback/request.php';
102 122 require_once dirname( __FILE__ ) . '/recover.php';
103 123
104 - $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
124 + $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
125 + $pubkey = isset($pubkey) ? WPRAccount::sanitizeKey($pubkey) : '';
126 + $rcvracc = WPRHelper::getRawParam('REQUEST', 'rcvracc');
105 127
106 - if (array_key_exists('rcvracc', $_REQUEST)) {
107 - $account = WPRRecover::find($bvsettings, $pubkey);
128 + if (isset($rcvracc)) {
129 + $bvctag = WPRHelper::getRawParam('REQUEST', 'bvctag');
130 + $bvctag = isset($bvctag) ? WPRAccount::sanitizeKey($bvctag) : null;
131 + $account = WPRRecover::find($bvsettings, $pubkey, $bvctag);
108 132 } else {
109 133 $account = WPRAccount::find($bvsettings, $pubkey);
110 134 }
111 135
112 - $request = new BVCallbackRequest($account, $_REQUEST, $bvsettings);
113 - $response = new BVCallbackResponse($request->bvb64cksize);
136 + $request = new WPRCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
137 + $response = new WPRCallbackResponse($request->bvb64cksize);
114 138
115 139 if ($request->authenticate() === 1) {
116 - define('WPRBASEPATH', plugin_dir_path(__FILE__));
140 + $bv_frm_tstng = WPRHelper::getRawParam('REQUEST', 'bv_frm_tstng');
141 + if (isset($bv_frm_tstng)) {
142 + require_once dirname(__FILE__) . '/form_testing/form_testing.php';
143 + $form_testing = new BVFormTesting($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
144 + $form_testing->init();
117 145
146 + } else {
147 + define('WPRBASEPATH', plugin_dir_path(__FILE__));
118 148
119 - require_once dirname( __FILE__ ) . '/callback/handler.php';
120 149
121 - $params = $request->processParams($_REQUEST);
122 - if ($params === false) {
123 - $response->terminate($request->corruptedParamsResp());
150 + require_once dirname( __FILE__ ) . '/callback/handler.php';
151 +
152 + $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
153 + if ($params === false) {
154 + $response->terminate($request->corruptedParamsResp());
155 + }
156 + $request->params = $params;
157 + $callback_handler = new WPRCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
158 + if ($request->is_aftershutdown) {
159 + $callback_handler->deferExecutionUntilShutdown();
160 + } else if ($request->is_afterload) {
161 + add_action('wp_loaded', array($callback_handler, 'execute'));
162 + } else if ($request->is_admin_ajax) {
163 + add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
164 + add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
165 + } else {
166 + $callback_handler->execute();
167 + }
124 168 }
125 - $request->params = $params;
126 - $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
127 - if ($request->is_afterload) {
128 - add_action('wp_loaded', array($callback_handler, 'execute'));
129 - } else if ($request->is_admin_ajax) {
130 - add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
131 - add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
132 - } else {
133 - $callback_handler->execute();
134 - }
135 169 } else {
136 170 $response->terminate($request->authFailedResp());
137 171 }
138 172 } else {
@@ -138,11 +172,17 @@
138 172 } else {
139 173 if ($bvinfo->hasValidDBVersion()) {
140 174 if ($bvinfo->isProtectModuleEnabled()) {
141 175 require_once dirname( __FILE__ ) . '/protect/protect.php';
142 - add_action('clear_pt_config', array('MCProtect', 'uninstall'));
143 - if ($bvinfo->isActivePlugin() && !(defined( 'WP_CLI' ) && WP_CLI)) {
144 - MCProtect::init(MCProtect::MODE_WP);
176 + //For backward compatibility.
177 + WPRProtect_V672::$settings = new WPRWPSettings();
178 + WPRProtect_V672::$db = new WPRWPDb();
179 + WPRProtect_V672::$info = new WPRInfo(WPRProtect_V672::$settings);
180 +
181 + add_action('wpr_clear_pt_config', array('WPRProtect_V672', 'uninstall'));
182 +
183 + if ($bvinfo->isActivePlugin()) {
184 + WPRProtect_V672::init(WPRProtect_V672::MODE_WP);
145 185 }
146 186 }
147 187
148 188 if ($bvinfo->isDynSyncModuleEnabled()) {
@@ -153,9 +193,9 @@
153 193 }
154 194
155 195 }
156 196 $bv_site_settings = $bvsettings->getOption('bv_site_settings');
157 - if (isset($bv_site_settings)) {
197 + if (is_array($bv_site_settings)) {
158 198 if (isset($bv_site_settings['wp_auto_updates'])) {
159 199 $wp_auto_updates = $bv_site_settings['wp_auto_updates'];
160 200 if (array_key_exists('block_auto_update_core', $wp_auto_updates)) {
161 201 add_filter('auto_update_core', '__return_false' );
@@ -171,8 +211,28 @@
171 211 if (array_key_exists('block_auto_update_translation', $wp_auto_updates)) {
172 212 add_filter('auto_update_translation', '__return_false' );
173 213 }
174 214 }
215 +
216 + if (isset($bv_site_settings['security_hardening'])) {
217 + $bv_security_hardening = $bv_site_settings['security_hardening'];
218 + if (is_array($bv_security_hardening) &&
219 + isset($bv_security_hardening['version']) &&
220 + $bv_security_hardening['version'] === 1) {
221 + if (isset($bv_security_hardening['disable_file_editor']) &&
222 + $bv_security_hardening['disable_file_editor'] === true &&
223 + !defined('DISALLOW_FILE_EDIT')) {
224 + define('DISALLOW_FILE_EDIT', true);
225 + }
226 +
227 + if (isset($bv_security_hardening['block_file_modifications']) &&
228 + $bv_security_hardening['block_file_modifications'] === true &&
229 + !defined('DISALLOW_FILE_MODS')) {
230 + define('DISALLOW_FILE_MODS', true);
231 + }
232 + }
233 + }
234 +
175 235 }
176 236
177 237 if (is_admin()) {
178 238 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
@@ -179,4 +239,17 @@
179 239 }
180 240
181 241 ##THIRDPARTYCACHINGMODULE##
182 242 }
243 +
244 +if (WPRWP2FA::isEnabled($bvsettings)) {
245 + $wp_2fa = new WPRWP2FA();
246 + $wp_2fa->init();
247 +}
248 +
249 +if (!empty($bvinfo->getLPWhitelabelInfo())) {
250 + $wp_login_whitelabel = new WPRWPLoginWhitelabel();
251 + $wp_login_whitelabel->init();
252 +}
253 +
254 +add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));
255 +##PLUGIN_LOADED_MODULE##