Plugin Directory

Changeset 3283432


Ignore:
Timestamp:
04/28/2025 01:19:16 PM (11 months ago)
Author:
freetobook
Message:

Version 1.1.1 - security patch for reported CSRF issue

Location:
freetobook-responsive-widget/trunk
Files:
3 edited

Legend:

Unmodified
Added
Removed
  • freetobook-responsive-widget/trunk/README.txt

    r3234622 r3283432  
    55Tested up to: 6.7.1
    66Requires PHP: 5.6
    7 Stable tag: 1.1
     7Stable tag: 1.1.1
    88License: GPLv2 or later
    99License URI: https://www.gnu.org/licenses/gpl-2.0.html
     
    3030== Changelog ==
    3131
     32= 1.1.1 =
     33* Security update
     34
    3235= 1.1 =
    3336* Update PHP syntax and required version to 5.6
  • freetobook-responsive-widget/trunk/freetobook-responsive-widget.php

    r2829476 r3283432  
    33* Plugin Name: Freetobook Responsive Widget
    44* Description: Add freetobook responsive widget to your wordpress site.
    5 * Version: 1.1
     5* Version: 1.1.1
    66* Author: freetobook.com
    77* Author URI: http://www.fretobook.com
  • freetobook-responsive-widget/trunk/includes/ftb-widget-admin-settings.php

    r2829471 r3283432  
    1919        $widgetToken = sanitize_text_field($widgetToken);
    2020        $widgetId = sanitize_text_field($widgetId);
     21
     22        if ( !isset($_POST['nonce_field'])
     23            || !wp_verify_nonce($_POST['nonce_field'], 'widget_settings_change' )
     24        ) {
     25            wp_die('An error occurred while saving your settings.');
     26        }
    2127
    2228        $valid = true;
     
    6571            <br />
    6672            <form method="post">';
     73
     74        $html .= wp_nonce_field('widget_settings_change', "nonce_field");
    6775
    6876        $html .= '
Note: See TracChangeset for help on using the changeset viewer.