Plugin Directory

Changeset 3049947


Ignore:
Timestamp:
03/12/2024 05:41:46 PM (2 years ago)
Author:
mingocommerce
Message:

fixed security vulnaribility

Location:
woo-product-enquiry
Files:
3 added
2 edited

Legend:

Unmodified
Added
Removed
  • woo-product-enquiry/trunk/readme.txt

    r2576584 r3049947  
    44Requires at least: 4.4
    55Tested up to: 5.8.0
    6 Stable tag: 2.3.4
     6Stable tag: 2.4.0
    77License: GPLv3
    88License URI: http://www.gnu.org/licenses/gpl-3.0.html
     
    5555
    5656== Upgrade Notice ==
     57
     58= 2.4.0 =
     59* Fixed Cross Site Scripting vulnaribility.
    5760
    5861= 2.3.2 =
  • woo-product-enquiry/trunk/woocommerce-product-enquiry-basic.php

    r2576584 r3049947  
    66Author: MingoCommerce
    77Author URI: http://www.mingocommerce.com
    8 Version: 2.3.4
     8Version: 2.4.0
    99Plugin URI: https://wordpress.org/plugins/woo-product-enquiry/
    1010WC tested up to: 4.4.1
     
    192192            );
    193193            foreach($mail_table_fields as $mail_table_field){
    194                 $data_to_be_saved['_pe_'.$mail_table_field['id']]   =   $_POST[$mail_table_field['id']];
     194                $data_to_be_saved['_pe_'.$mail_table_field['id']]   =   sanitize_text_field($_POST[$mail_table_field['id']]);
    195195            }
    196196            $new_enquiry    =   array(
     
    217217        foreach($fields as $key =>  $field){
    218218            if(isset($field['validation']) && is_array($field['validation'])){
    219                 $field['value'] =   $_POST[$key];               
    220                
     219                $field['value'] =   sanitize_text_field($_POST[$key]);
    221220                foreach($field['validation'] as $validation){
    222221                    $v  =   $this->validate_field($field, $validation);
Note: See TracChangeset for help on using the changeset viewer.