PluginProbe
The WP Remote WordPress Plugin / trunk
The WP Remote WordPress Plugin vtrunk
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | plugin.php +83 -59 5.68trunk View file →
@@ -4,10 +4,12 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 5.68
8 +Version: 6.72
9 9 Network: True
10 +License: GPLv2 or later
11 +License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
10 12 */
11 13
12 14 /* Copyright 2017 WP Remote (email : support@wpremote.com)
13 15
@@ -37,8 +39,13 @@
37 39 require_once dirname( __FILE__ ) . '/wp_actions.php';
38 40 require_once dirname( __FILE__ ) . '/info.php';
39 41 require_once dirname( __FILE__ ) . '/account.php';
40 42 require_once dirname( __FILE__ ) . '/helper.php';
43 +require_once dirname( __FILE__ ) . '/wp_file_system.php';
44 +require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
45 +
46 +require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
47 +
41 48 ##WPCACHEMODULE##
42 49
43 50
44 51 $bvsettings = new WPRWPSettings();
@@ -53,15 +60,18 @@
53 60 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
54 61 register_activation_hook(__FILE__, array($wp_action, 'activate'));
55 62 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
56 63
64 +
57 65 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
58 -add_action('clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
66 +add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
67 +
59 68 ##SOADDUNINSTALLACTION##
60 69
61 70 ##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
62 71
63 72 ##WPCLIMODULE##
73 +
64 74 if (is_admin()) {
65 75 require_once dirname( __FILE__ ) . '/wp_admin.php';
66 76 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
67 77 add_action('admin_init', array($wpadmin, 'initHandler'));
@@ -74,18 +84,24 @@
74 84 add_action('admin_menu', array($wpadmin, 'menu'));
75 85 }
76 86 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
77 87 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
88 +
89 + ##MG_AJAX_ACTIONS##
90 + ##POPUP_ON_DEACTIVATION##
78 91 add_action('admin_notices', array($wpadmin, 'activateWarning'));
79 92 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
80 - ##ALPURGECACHEFUNCTION##
81 - ##ALADMINMENU##
82 93 }
83 94
84 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
85 - $_REQUEST = array_merge($_GET, $_POST);
95 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
96 + $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
86 97 }
87 98
99 +#Service active check
100 +if ($bvinfo->config != false) {
101 + add_action('wpr_remove_bv_preload_include', array($wp_action, 'removeBVPreload'));
102 +}
103 +
88 104 require_once dirname( __FILE__ ) . '/php_error_monitoring/monitoring.php';
89 105 WPRWPPHPErrorMonitoring::init();
90 106
91 107 if ($bvinfo->hasValidDBVersion()) {
@@ -95,66 +111,39 @@
95 111 $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
96 112 $actlog->init();
97 113 }
98 114
99 - if ($bvinfo->isServiceActive('maintenance_mode')) {
100 - require_once dirname( __FILE__ ). '/maintenance/wp_maintenance.php';
101 - $bvconfig = $bvinfo->config;
102 - $maintenance = new BVWPMaintenance($bvconfig['maintenance_mode']);
103 - $maintenance->init();
104 - }
105 -
115 + ##MAINTENANCEMODULE##
106 116 }
107 117
108 -if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
118 +if (WPRHelper::getRawParam('REQUEST', 'bvplugname') == "wpremote") {
109 119 require_once dirname( __FILE__ ) . '/callback/base.php';
110 120 require_once dirname( __FILE__ ) . '/callback/response.php';
111 121 require_once dirname( __FILE__ ) . '/callback/request.php';
112 122 require_once dirname( __FILE__ ) . '/recover.php';
113 123
114 - $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
124 + $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
125 + $pubkey = isset($pubkey) ? WPRAccount::sanitizeKey($pubkey) : '';
126 + $rcvracc = WPRHelper::getRawParam('REQUEST', 'rcvracc');
115 127
116 - if (array_key_exists('rcvracc', $_REQUEST)) {
117 - $account = WPRRecover::find($bvsettings, $pubkey);
128 + if (isset($rcvracc)) {
129 + $bvctag = WPRHelper::getRawParam('REQUEST', 'bvctag');
130 + $bvctag = isset($bvctag) ? WPRAccount::sanitizeKey($bvctag) : null;
131 + $account = WPRRecover::find($bvsettings, $pubkey, $bvctag);
118 132 } else {
119 133 $account = WPRAccount::find($bvsettings, $pubkey);
120 134 }
121 135
122 - $request = new BVCallbackRequest($account, $_REQUEST, $bvsettings);
123 - $response = new BVCallbackResponse($request->bvb64cksize);
136 + $request = new WPRCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
137 + $response = new WPRCallbackResponse($request->bvb64cksize);
124 138
125 139 if ($request->authenticate() === 1) {
126 - if (array_key_exists('bv_ignr_frm_cptch', $_REQUEST)) {
127 - #handling of Contact Forms 7
128 - add_filter('wpcf7_skip_spam_check', '__return_true', PHP_INT_MAX, 2);
140 + $bv_frm_tstng = WPRHelper::getRawParam('REQUEST', 'bv_frm_tstng');
141 + if (isset($bv_frm_tstng)) {
142 + require_once dirname(__FILE__) . '/form_testing/form_testing.php';
143 + $form_testing = new BVFormTesting($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
144 + $form_testing->init();
129 145
130 - #handling of Formidable plugin
131 - add_filter('frm_is_field_hidden', '__return_true', PHP_INT_MAX, 3);
132 -
133 - #handling of WP Forms plugin
134 - add_filter('wpforms_process_bypass_captcha', '__return_true', PHP_INT_MAX, 3);
135 -
136 - #handling of Forminator plugin
137 - if (defined('WP_PLUGIN_DIR')) {
138 - $abstractFrontActionFilePath = WP_PLUGIN_DIR . '/forminator/library/abstracts/abstract-class-front-action.php';
139 - $frontActionFilePath = WP_PLUGIN_DIR . '/forminator/library/modules/custom-forms/front/front-action.php';
140 -
141 - if (file_exists($abstractFrontActionFilePath) && file_exists($frontActionFilePath)) {
142 - require_once $abstractFrontActionFilePath;
143 - require_once $frontActionFilePath;
144 - if (class_exists('Forminator_CForm_Front_Action')) {
145 - Forminator_CForm_Front_Action::$hidden_fields[] = "bv-stripe-";
146 - }
147 - }
148 - }
149 -
150 - #handling of CleanTalk Antispam plugin
151 - add_action('init', function() {
152 - global $apbct;
153 - if (isset($apbct) && is_object($apbct)) {
154 - $apbct->settings['forms__contact_forms_test'] = 0;
155 - }
156 - });
157 146 } else {
158 147 define('WPRBASEPATH', plugin_dir_path(__FILE__));
159 148
160 149
@@ -159,15 +148,17 @@
159 148
160 149
161 150 require_once dirname( __FILE__ ) . '/callback/handler.php';
162 151
163 - $params = $request->processParams($_REQUEST);
152 + $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
164 153 if ($params === false) {
165 154 $response->terminate($request->corruptedParamsResp());
166 155 }
167 156 $request->params = $params;
168 - $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
169 - if ($request->is_afterload) {
157 + $callback_handler = new WPRCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
158 + if ($request->is_aftershutdown) {
159 + $callback_handler->deferExecutionUntilShutdown();
160 + } else if ($request->is_afterload) {
170 161 add_action('wp_loaded', array($callback_handler, 'execute'));
171 162 } else if ($request->is_admin_ajax) {
172 163 add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
173 164 add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
@@ -182,16 +173,16 @@
182 173 if ($bvinfo->hasValidDBVersion()) {
183 174 if ($bvinfo->isProtectModuleEnabled()) {
184 175 require_once dirname( __FILE__ ) . '/protect/protect.php';
185 176 //For backward compatibility.
186 - WPRProtect_V568::$settings = new WPRWPSettings();
187 - WPRProtect_V568::$db = new WPRWPDb();
188 - WPRProtect_V568::$info = new WPRInfo(WPRProtect_V568::$settings);
177 + WPRProtect_V672::$settings = new WPRWPSettings();
178 + WPRProtect_V672::$db = new WPRWPDb();
179 + WPRProtect_V672::$info = new WPRInfo(WPRProtect_V672::$settings);
189 180
190 - add_action('clear_pt_config', array('WPRProtect_V568', 'uninstall'));
181 + add_action('wpr_clear_pt_config', array('WPRProtect_V672', 'uninstall'));
191 182
192 183 if ($bvinfo->isActivePlugin()) {
193 - WPRProtect_V568::init(WPRProtect_V568::MODE_WP);
184 + WPRProtect_V672::init(WPRProtect_V672::MODE_WP);
194 185 }
195 186 }
196 187
197 188 if ($bvinfo->isDynSyncModuleEnabled()) {
@@ -202,9 +193,9 @@
202 193 }
203 194
204 195 }
205 196 $bv_site_settings = $bvsettings->getOption('bv_site_settings');
206 - if (isset($bv_site_settings)) {
197 + if (is_array($bv_site_settings)) {
207 198 if (isset($bv_site_settings['wp_auto_updates'])) {
208 199 $wp_auto_updates = $bv_site_settings['wp_auto_updates'];
209 200 if (array_key_exists('block_auto_update_core', $wp_auto_updates)) {
210 201 add_filter('auto_update_core', '__return_false' );
@@ -220,8 +211,28 @@
220 211 if (array_key_exists('block_auto_update_translation', $wp_auto_updates)) {
221 212 add_filter('auto_update_translation', '__return_false' );
222 213 }
223 214 }
215 +
216 + if (isset($bv_site_settings['security_hardening'])) {
217 + $bv_security_hardening = $bv_site_settings['security_hardening'];
218 + if (is_array($bv_security_hardening) &&
219 + isset($bv_security_hardening['version']) &&
220 + $bv_security_hardening['version'] === 1) {
221 + if (isset($bv_security_hardening['disable_file_editor']) &&
222 + $bv_security_hardening['disable_file_editor'] === true &&
223 + !defined('DISALLOW_FILE_EDIT')) {
224 + define('DISALLOW_FILE_EDIT', true);
225 + }
226 +
227 + if (isset($bv_security_hardening['block_file_modifications']) &&
228 + $bv_security_hardening['block_file_modifications'] === true &&
229 + !defined('DISALLOW_FILE_MODS')) {
230 + define('DISALLOW_FILE_MODS', true);
231 + }
232 + }
233 + }
234 +
224 235 }
225 236
226 237 if (is_admin()) {
227 238 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
@@ -227,5 +238,18 @@
227 238 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
228 239 }
229 240
230 241 ##THIRDPARTYCACHINGMODULE##
231 -}
242 +}
243 +
244 +if (WPRWP2FA::isEnabled($bvsettings)) {
245 + $wp_2fa = new WPRWP2FA();
246 + $wp_2fa->init();
247 +}
248 +
249 +if (!empty($bvinfo->getLPWhitelabelInfo())) {
250 + $wp_login_whitelabel = new WPRWPLoginWhitelabel();
251 + $wp_login_whitelabel->init();
252 +}
253 +
254 +add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));
255 +##PLUGIN_LOADED_MODULE##