PluginProbe
The WP Remote WordPress Plugin / trunk
The WP Remote WordPress Plugin vtrunk
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | plugin.php +75 -58 5.73trunk View file →
@@ -4,10 +4,12 @@
4 4 Plugin URI: https://wpremote.com
5 5 Description: Manage your WordPress site with <a href="https://wpremote.com/">WP Remote</a>.
6 6 Author: WP Remote
7 7 Author URI: https://wpremote.com
8 -Version: 5.73
8 +Version: 6.72
9 9 Network: True
10 +License: GPLv2 or later
11 +License URI: [http://www.gnu.org/licenses/gpl-2.0.html](http://www.gnu.org/licenses/gpl-2.0.html)
10 12 */
11 13
12 14 /* Copyright 2017 WP Remote (email : support@wpremote.com)
13 15
@@ -37,10 +39,13 @@
37 39 require_once dirname( __FILE__ ) . '/wp_actions.php';
38 40 require_once dirname( __FILE__ ) . '/info.php';
39 41 require_once dirname( __FILE__ ) . '/account.php';
40 42 require_once dirname( __FILE__ ) . '/helper.php';
43 +require_once dirname( __FILE__ ) . '/wp_file_system.php';
41 44 require_once dirname( __FILE__ ) . '/wp_2fa/wp_2fa.php';
42 45
46 +require_once dirname( __FILE__ ) . '/wp_login_whitelabel.php';
47 +
43 48 ##WPCACHEMODULE##
44 49
45 50
46 51 $bvsettings = new WPRWPSettings();
@@ -55,15 +60,18 @@
55 60 register_uninstall_hook(__FILE__, array('WPRWPAction', 'uninstall'));
56 61 register_activation_hook(__FILE__, array($wp_action, 'activate'));
57 62 register_deactivation_hook(__FILE__, array($wp_action, 'deactivate'));
58 63
64 +
59 65 add_action('wp_footer', array($wp_action, 'footerHandler'), 100);
60 66 add_action('wpr_clear_bv_services_config', array($wp_action, 'clear_bv_services_config'));
67 +
61 68 ##SOADDUNINSTALLACTION##
62 69
63 70 ##DISABLE_OTHER_OPTIMIZATION_PLUGINS##
64 71
65 72 ##WPCLIMODULE##
73 +
66 74 if (is_admin()) {
67 75 require_once dirname( __FILE__ ) . '/wp_admin.php';
68 76 $wpadmin = new WPRWPAdmin($bvsettings, $bvsiteinfo);
69 77 add_action('admin_init', array($wpadmin, 'initHandler'));
@@ -76,16 +84,17 @@
76 84 add_action('admin_menu', array($wpadmin, 'menu'));
77 85 }
78 86 add_filter('plugin_action_links', array($wpadmin, 'settingsLink'), 10, 2);
79 87 add_action('admin_head', array($wpadmin, 'removeAdminNotices'), 3);
88 +
89 + ##MG_AJAX_ACTIONS##
90 + ##POPUP_ON_DEACTIVATION##
80 91 add_action('admin_notices', array($wpadmin, 'activateWarning'));
81 92 add_action('admin_enqueue_scripts', array($wpadmin, 'wprsecAdminMenu'));
82 - ##ALPURGECACHEFUNCTION##
83 - ##ALADMINMENU##
84 93 }
85 94
86 -if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) {
87 - $_REQUEST = array_merge($_GET, $_POST);
95 +if ((array_key_exists('bvreqmerge', $_POST)) || (array_key_exists('bvreqmerge', $_GET))) { // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
96 + $_REQUEST = array_merge($_GET, $_POST); // phpcs:ignore WordPress.Security.NonceVerification.Missing, WordPress.Security.NonceVerification.Recommended
88 97 }
89 98
90 99 #Service active check
91 100 if ($bvinfo->config != false) {
@@ -102,66 +111,39 @@
102 111 $actlog = new BVWPActLog($bvdb, $bvsettings, $bvinfo, $bvconfig['activity_log']);
103 112 $actlog->init();
104 113 }
105 114
106 - if ($bvinfo->isServiceActive('maintenance_mode')) {
107 - require_once dirname( __FILE__ ). '/maintenance/wp_maintenance.php';
108 - $bvconfig = $bvinfo->config;
109 - $maintenance = new BVWPMaintenance($bvconfig['maintenance_mode']);
110 - $maintenance->init();
111 - }
112 -
115 + ##MAINTENANCEMODULE##
113 116 }
114 117
115 -if ((array_key_exists('bvplugname', $_REQUEST)) && ($_REQUEST['bvplugname'] == "wpremote")) {
118 +if (WPRHelper::getRawParam('REQUEST', 'bvplugname') == "wpremote") {
116 119 require_once dirname( __FILE__ ) . '/callback/base.php';
117 120 require_once dirname( __FILE__ ) . '/callback/response.php';
118 121 require_once dirname( __FILE__ ) . '/callback/request.php';
119 122 require_once dirname( __FILE__ ) . '/recover.php';
120 123
121 - $pubkey = WPRAccount::sanitizeKey($_REQUEST['pubkey']);
124 + $pubkey = WPRHelper::getRawParam('REQUEST', 'pubkey');
125 + $pubkey = isset($pubkey) ? WPRAccount::sanitizeKey($pubkey) : '';
126 + $rcvracc = WPRHelper::getRawParam('REQUEST', 'rcvracc');
122 127
123 - if (array_key_exists('rcvracc', $_REQUEST)) {
124 - $account = WPRRecover::find($bvsettings, $pubkey);
128 + if (isset($rcvracc)) {
129 + $bvctag = WPRHelper::getRawParam('REQUEST', 'bvctag');
130 + $bvctag = isset($bvctag) ? WPRAccount::sanitizeKey($bvctag) : null;
131 + $account = WPRRecover::find($bvsettings, $pubkey, $bvctag);
125 132 } else {
126 133 $account = WPRAccount::find($bvsettings, $pubkey);
127 134 }
128 135
129 - $request = new BVCallbackRequest($account, $_REQUEST, $bvsettings);
130 - $response = new BVCallbackResponse($request->bvb64cksize);
136 + $request = new WPRCallbackRequest($account, $_REQUEST, $bvsettings); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
137 + $response = new WPRCallbackResponse($request->bvb64cksize);
131 138
132 139 if ($request->authenticate() === 1) {
133 - if (array_key_exists('bv_ignr_frm_cptch', $_REQUEST)) {
134 - #handling of Contact Forms 7
135 - add_filter('wpcf7_skip_spam_check', '__return_true', PHP_INT_MAX, 2);
140 + $bv_frm_tstng = WPRHelper::getRawParam('REQUEST', 'bv_frm_tstng');
141 + if (isset($bv_frm_tstng)) {
142 + require_once dirname(__FILE__) . '/form_testing/form_testing.php';
143 + $form_testing = new BVFormTesting($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
144 + $form_testing->init();
136 145
137 - #handling of Formidable plugin
138 - add_filter('frm_is_field_hidden', '__return_true', PHP_INT_MAX, 3);
139 -
140 - #handling of WP Forms plugin
141 - add_filter('wpforms_process_bypass_captcha', '__return_true', PHP_INT_MAX, 3);
142 -
143 - #handling of Forminator plugin
144 - if (defined('WP_PLUGIN_DIR')) {
145 - $abstractFrontActionFilePath = WP_PLUGIN_DIR . '/forminator/library/abstracts/abstract-class-front-action.php';
146 - $frontActionFilePath = WP_PLUGIN_DIR . '/forminator/library/modules/custom-forms/front/front-action.php';
147 -
148 - if (file_exists($abstractFrontActionFilePath) && file_exists($frontActionFilePath)) {
149 - require_once $abstractFrontActionFilePath;
150 - require_once $frontActionFilePath;
151 - if (class_exists('Forminator_CForm_Front_Action')) {
152 - Forminator_CForm_Front_Action::$hidden_fields[] = "bv-stripe-";
153 - }
154 - }
155 - }
156 -
157 - #handling of CleanTalk Antispam plugin
158 - add_action('init', function() {
159 - global $apbct;
160 - if (isset($apbct) && is_object($apbct)) {
161 - $apbct->settings['forms__contact_forms_test'] = 0;
162 - }
163 - });
164 146 } else {
165 147 define('WPRBASEPATH', plugin_dir_path(__FILE__));
166 148
167 149
@@ -166,15 +148,17 @@
166 148
167 149
168 150 require_once dirname( __FILE__ ) . '/callback/handler.php';
169 151
170 - $params = $request->processParams($_REQUEST);
152 + $params = $request->processParams($_REQUEST); // phpcs:ignore WordPress.Security.NonceVerification.Recommended
171 153 if ($params === false) {
172 154 $response->terminate($request->corruptedParamsResp());
173 155 }
174 156 $request->params = $params;
175 - $callback_handler = new BVCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
176 - if ($request->is_afterload) {
157 + $callback_handler = new WPRCallbackHandler($bvdb, $bvsettings, $bvsiteinfo, $request, $account, $response);
158 + if ($request->is_aftershutdown) {
159 + $callback_handler->deferExecutionUntilShutdown();
160 + } else if ($request->is_afterload) {
177 161 add_action('wp_loaded', array($callback_handler, 'execute'));
178 162 } else if ($request->is_admin_ajax) {
179 163 add_action('wp_ajax_bvadm', array($callback_handler, 'bvAdmExecuteWithUser'));
180 164 add_action('wp_ajax_nopriv_bvadm', array($callback_handler, 'bvAdmExecuteWithoutUser'));
@@ -189,16 +173,16 @@
189 173 if ($bvinfo->hasValidDBVersion()) {
190 174 if ($bvinfo->isProtectModuleEnabled()) {
191 175 require_once dirname( __FILE__ ) . '/protect/protect.php';
192 176 //For backward compatibility.
193 - WPRProtect_V573::$settings = new WPRWPSettings();
194 - WPRProtect_V573::$db = new WPRWPDb();
195 - WPRProtect_V573::$info = new WPRInfo(WPRProtect_V573::$settings);
177 + WPRProtect_V672::$settings = new WPRWPSettings();
178 + WPRProtect_V672::$db = new WPRWPDb();
179 + WPRProtect_V672::$info = new WPRInfo(WPRProtect_V672::$settings);
196 180
197 - add_action('wpr_clear_pt_config', array('WPRProtect_V573', 'uninstall'));
181 + add_action('wpr_clear_pt_config', array('WPRProtect_V672', 'uninstall'));
198 182
199 183 if ($bvinfo->isActivePlugin()) {
200 - WPRProtect_V573::init(WPRProtect_V573::MODE_WP);
184 + WPRProtect_V672::init(WPRProtect_V672::MODE_WP);
201 185 }
202 186 }
203 187
204 188 if ($bvinfo->isDynSyncModuleEnabled()) {
@@ -209,9 +193,9 @@
209 193 }
210 194
211 195 }
212 196 $bv_site_settings = $bvsettings->getOption('bv_site_settings');
213 - if (isset($bv_site_settings)) {
197 + if (is_array($bv_site_settings)) {
214 198 if (isset($bv_site_settings['wp_auto_updates'])) {
215 199 $wp_auto_updates = $bv_site_settings['wp_auto_updates'];
216 200 if (array_key_exists('block_auto_update_core', $wp_auto_updates)) {
217 201 add_filter('auto_update_core', '__return_false' );
@@ -227,8 +211,28 @@
227 211 if (array_key_exists('block_auto_update_translation', $wp_auto_updates)) {
228 212 add_filter('auto_update_translation', '__return_false' );
229 213 }
230 214 }
215 +
216 + if (isset($bv_site_settings['security_hardening'])) {
217 + $bv_security_hardening = $bv_site_settings['security_hardening'];
218 + if (is_array($bv_security_hardening) &&
219 + isset($bv_security_hardening['version']) &&
220 + $bv_security_hardening['version'] === 1) {
221 + if (isset($bv_security_hardening['disable_file_editor']) &&
222 + $bv_security_hardening['disable_file_editor'] === true &&
223 + !defined('DISALLOW_FILE_EDIT')) {
224 + define('DISALLOW_FILE_EDIT', true);
225 + }
226 +
227 + if (isset($bv_security_hardening['block_file_modifications']) &&
228 + $bv_security_hardening['block_file_modifications'] === true &&
229 + !defined('DISALLOW_FILE_MODS')) {
230 + define('DISALLOW_FILE_MODS', true);
231 + }
232 + }
233 + }
234 +
231 235 }
232 236
233 237 if (is_admin()) {
234 238 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
@@ -234,5 +238,18 @@
234 238 add_filter('site_transient_update_plugins', array($wpadmin, 'hidePluginUpdate'));
235 239 }
236 240
237 241 ##THIRDPARTYCACHINGMODULE##
238 -}
242 +}
243 +
244 +if (WPRWP2FA::isEnabled($bvsettings)) {
245 + $wp_2fa = new WPRWP2FA();
246 + $wp_2fa->init();
247 +}
248 +
249 +if (!empty($bvinfo->getLPWhitelabelInfo())) {
250 + $wp_login_whitelabel = new WPRWPLoginWhitelabel();
251 + $wp_login_whitelabel->init();
252 +}
253 +
254 +add_action('wpr_clear_wp_2fa_config', array($wp_action, 'clear_wp_2fa_config'));
255 +##PLUGIN_LOADED_MODULE##