PluginProbe
The WP Remote WordPress Plugin / trunk
The WP Remote WordPress Plugin vtrunk
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | plugin.php +86 -56 5.65trunk View file →
@@ -4,10 +4,12 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 5.65
8 +Version: 6.72
9 9 Network: True
10 +License: GPLv2 or later
11 +License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
10 12 */
11 13
12 14 /* Copyright 2017 WP Remote (email : support@wpremote.com)
13 15
@@ -37,8 +39,13 @@
37 39 require_once dirname( __FILE__ ) . '/wp_actions.php';
38 40 require_once dirname( __FILE__ ) . '/info.php';
39 41 require_once dirname( __FILE__ ) . '/account.php';
40 42 require_once dirname( __FILE__ ) . '/helper.php';
43 +require_once dirname( __FILE__ ) . '/wp_file_system.php';
44 +require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
45 +
46 +require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
47 +
41 48 ##WPCACHEMODULE##
42 49
43 50
44 51 $bvsettings = new WPRWPSettings();
@@ -53,15 +60,18 @@
53 60 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
54 61 register_activation_hook(__FILE__, array($wp_action, 'activate'));
55 62 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
56 63
64 +
57 65 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
58 -add_action('clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
66 +add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
67 +
59 68 ##SOADDUNINSTALLACTION##
60 69
61 70 ##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
62 71
63 72 ##WPCLIMODULE##
73 +
64 74 if (is_admin()) {
65 75 require_once dirname( __FILE__ ) . '/wp_admin.php';
66 76 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
67 77 add_action('admin_init', array($wpadmin, 'initHandler'));
@@ -74,18 +84,24 @@
74 84 add_action('admin_menu', array($wpadmin, 'menu'));
75 85 }
76 86 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
77 87 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
88 +
89 + ##MG_AJAX_ACTIONS##
90 + ##POPUP_ON_DEACTIVATION##
78 91 add_action('admin_notices', array($wpadmin, 'activateWarning'));
79 92 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
80 - ##ALPURGECACHEFUNCTION##
81 - ##ALADMINMENU##
82 93 }
83 94
84 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
85 - $_REQUEST = array_merge($_GET, $_POST);
95 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
96 + $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
86 97 }
87 98
99 +#Service active check
100 +if ($bvinfo->config != false) {
101 + add_action('wpr_remove_bv_preload_include', array($wp_action, 'removeBVPreload'));
102 +}
103 +
88 104 require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
89 105 WPRWPPHPErrorMonitoring::init();
90 106
91 107 if ($bvinfo->hasValidDBVersion()) {
@@ -95,66 +111,39 @@
95 111 $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
96 112 $actlog->init();
97 113 }
98 114
99 - if ($bvinfo->isServiceActive('maintenance_mode')) {
100 - require_once dirname( __FILE__ ). '/maintenance/wp_maintenance.php';
101 - $bvconfig = $bvinfo->config;
102 - $maintenance = new BVWPMaintenance($bvconfig['maintenance_mode']);
103 - $maintenance->init();
104 - }
105 -
115 + ##MAINTENANCEMODULE##
106 116 }
107 117
108 -if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
118 +if (WPRHelper::getRawParam('REQUEST', 'bvplugname') == "wpremote") {
109 119 require_once dirname( __FILE__ ) . '/callback/base.php';
110 120 require_once dirname( __FILE__ ) . '/callback/response.php';
111 121 require_once dirname( __FILE__ ) . '/callback/request.php';
112 122 require_once dirname( __FILE__ ) . '/recover.php';
113 123
114 - $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
124 + $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
125 + $pubkey = isset($pubkey) ? WPRAccount::sanitizeKey($pubkey) : '';
126 + $rcvracc = WPRHelper::getRawParam('REQUEST', 'rcvracc');
115 127
116 - if (array_key_exists('rcvracc', $_REQUEST)) {
117 - $account = WPRRecover::find($bvsettings, $pubkey);
128 + if (isset($rcvracc)) {
129 + $bvctag = WPRHelper::getRawParam('REQUEST', 'bvctag');
130 + $bvctag = isset($bvctag) ? WPRAccount::sanitizeKey($bvctag) : null;
131 + $account = WPRRecover::find($bvsettings, $pubkey, $bvctag);
118 132 } else {
119 133 $account = WPRAccount::find($bvsettings, $pubkey);
120 134 }
121 135
122 - $request = new BVCallbackRequest($account, $_REQUEST, $bvsettings);
123 - $response = new BVCallbackResponse($request->bvb64cksize);
136 + $request = new WPRCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
137 + $response = new WPRCallbackResponse($request->bvb64cksize);
124 138
125 139 if ($request->authenticate() === 1) {
126 - if (array_key_exists('bv_ignr_frm_cptch', $_REQUEST)) {
127 - #handling of Contact Forms 7
128 - add_filter('wpcf7_skip_spam_check', '__return_true', PHP_INT_MAX, 2);
140 + $bv_frm_tstng = WPRHelper::getRawParam('REQUEST', 'bv_frm_tstng');
141 + if (isset($bv_frm_tstng)) {
142 + require_once dirname(__FILE__) . '/form_testing/form_testing.php';
143 + $form_testing = new BVFormTesting($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
144 + $form_testing->init();
129 145
130 - #handling of Formidable plugin
131 - add_filter('frm_is_field_hidden', '__return_true', PHP_INT_MAX, 3);
132 -
133 - #handling of WP Forms plugin
134 - add_filter('wpforms_process_bypass_captcha', '__return_true', PHP_INT_MAX, 3);
135 -
136 - #handling of Forminator plugin
137 - if (defined('WP_PLUGIN_DIR')) {
138 - $abstractFrontActionFilePath = WP_PLUGIN_DIR . '/forminator/library/abstracts/abstract-class-front-action.php';
139 - $frontActionFilePath = WP_PLUGIN_DIR . '/forminator/library/modules/custom-forms/front/front-action.php';
140 -
141 - if (file_exists($abstractFrontActionFilePath) && file_exists($frontActionFilePath)) {
142 - require_once $abstractFrontActionFilePath;
143 - require_once $frontActionFilePath;
144 - if (class_exists('Forminator_CForm_Front_Action')) {
145 - Forminator_CForm_Front_Action::$hidden_fields[] = "bv-stripe-";
146 - }
147 - }
148 - }
149 -
150 - #handling of CleanTalk Antispam plugin
151 - add_action('init', function() {
152 - global $apbct;
153 - if (isset($apbct) && is_object($apbct)) {
154 - $apbct->settings['forms__contact_forms_test'] = 0;
155 - }
156 - });
157 146 } else {
158 147 define('WPRBASEPATH', plugin_dir_path(__FILE__));
159 148
160 149
@@ -159,15 +148,17 @@
159 148
160 149
161 150 require_once dirname( __FILE__ ) . '/callback/handler.php';
162 151
163 - $params = $request->processParams($_REQUEST);
152 + $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
164 153 if ($params === false) {
165 154 $response->terminate($request->corruptedParamsResp());
166 155 }
167 156 $request->params = $params;
168 - $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
169 - if ($request->is_afterload) {
157 + $callback_handler = new WPRCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
158 + if ($request->is_aftershutdown) {
159 + $callback_handler->deferExecutionUntilShutdown();
160 + } else if ($request->is_afterload) {
170 161 add_action('wp_loaded', array($callback_handler, 'execute'));
171 162 } else if ($request->is_admin_ajax) {
172 163 add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
173 164 add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
@@ -181,11 +172,17 @@
181 172 } else {
182 173 if ($bvinfo->hasValidDBVersion()) {
183 174 if ($bvinfo->isProtectModuleEnabled()) {
184 175 require_once dirname( __FILE__ ) . '/protect/protect.php';
185 - add_action('clear_pt_config', array('WPRProtect_V565', 'uninstall'));
176 + //For backward compatibility.
177 + WPRProtect_V672::$settings = new WPRWPSettings();
178 + WPRProtect_V672::$db = new WPRWPDb();
179 + WPRProtect_V672::$info = new WPRInfo(WPRProtect_V672::$settings);
180 +
181 + add_action('wpr_clear_pt_config', array('WPRProtect_V672', 'uninstall'));
182 +
186 183 if ($bvinfo->isActivePlugin()) {
187 - WPRProtect_V565::init(WPRProtect_V565::MODE_WP);
184 + WPRProtect_V672::init(WPRProtect_V672::MODE_WP);
188 185 }
189 186 }
190 187
191 188 if ($bvinfo->isDynSyncModuleEnabled()) {
@@ -196,9 +193,9 @@
196 193 }
197 194
198 195 }
199 196 $bv_site_settings = $bvsettings->getOption('bv_site_settings');
200 - if (isset($bv_site_settings)) {
197 + if (is_array($bv_site_settings)) {
201 198 if (isset($bv_site_settings['wp_auto_updates'])) {
202 199 $wp_auto_updates = $bv_site_settings['wp_auto_updates'];
203 200 if (array_key_exists('block_auto_update_core', $wp_auto_updates)) {
204 201 add_filter('auto_update_core', '__return_false' );
@@ -214,8 +211,28 @@
214 211 if (array_key_exists('block_auto_update_translation', $wp_auto_updates)) {
215 212 add_filter('auto_update_translation', '__return_false' );
216 213 }
217 214 }
215 +
216 + if (isset($bv_site_settings['security_hardening'])) {
217 + $bv_security_hardening = $bv_site_settings['security_hardening'];
218 + if (is_array($bv_security_hardening) &&
219 + isset($bv_security_hardening['version']) &&
220 + $bv_security_hardening['version'] === 1) {
221 + if (isset($bv_security_hardening['disable_file_editor']) &&
222 + $bv_security_hardening['disable_file_editor'] === true &&
223 + !defined('DISALLOW_FILE_EDIT')) {
224 + define('DISALLOW_FILE_EDIT', true);
225 + }
226 +
227 + if (isset($bv_security_hardening['block_file_modifications']) &&
228 + $bv_security_hardening['block_file_modifications'] === true &&
229 + !defined('DISALLOW_FILE_MODS')) {
230 + define('DISALLOW_FILE_MODS', true);
231 + }
232 + }
233 + }
234 +
218 235 }
219 236
220 237 if (is_admin()) {
221 238 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
@@ -221,5 +238,18 @@
221 238 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
222 239 }
223 240
224 241 ##THIRDPARTYCACHINGMODULE##
225 -}
242 +}
243 +
244 +if (WPRWP2FA::isEnabled($bvsettings)) {
245 + $wp_2fa = new WPRWP2FA();
246 + $wp_2fa->init();
247 +}
248 +
249 +if (!empty($bvinfo->getLPWhitelabelInfo())) {
250 + $wp_login_whitelabel = new WPRWPLoginWhitelabel();
251 + $wp_login_whitelabel->init();
252 +}
253 +
254 +add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));
255 +##PLUGIN_LOADED_MODULE##